This month: 17 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-20253
Splunk · Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Detected Jun 18 · 3-day patch deadline
CVE-2026-48907
Widget Factory · Joomla Content Editor
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Detected Jun 16 · 3-day patch deadline
CVE-2026-54420
LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Detected Jun 15 · 3-day patch deadline

KEV Intelligence Brief — Week of June 22, 2026

Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Reference Period: CVEs added to CISA KEV, June 9–18, 2026 Classification: TLP:CLEAR

Unauthenticated and Pre-Auth Exploitation: The Week's Dominant Threat Pattern

The most alarming cluster in this week's KEV additions shares a common trait that should immediately focus operational attention: no authentication required to exploit. Three entries fall into this category, and all three carry patch deadlines that are either already past or within hours of this brief.

CVE-2026-20253 (Splunk Enterprise) is the most operationally disruptive entry of the week. An unauthenticated attacker can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint — a capability that translates directly to service disruption, log destruction, or a foothold for follow-on code execution. The patch deadline was June 21, meaning federal contractors and BOD 26-04-scoped organizations are already in violation if remediation is not documented. Given Splunk's role as a SIEM backbone across federal and critical infrastructure environments, a compromised Splunk instance doesn't just represent one asset at risk — it can blind your entire detection capability. Isolate the PostgreSQL sidecar service at the network layer immediately if patching has not been completed, and treat any Splunk instance with internet-facing exposure as potentially compromised pending forensic triage per CISA's Forensics Triage Requirements.

CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) carries a similarly severe profile: unauthenticated full system takeover. The patch deadline was June 15 — a week overdue as of today. PeopleSoft environments frequently host HR, payroll, and student records data, making this a high-value target for ransomware actors and nation-state affiliates with financial motives. If your organization cannot immediately patch, restrict access to PeopleSoft web interfaces to known IP ranges or place the system behind a VPN gateway as an interim control. Credential rotation for all service accounts integrated with PeopleSoft is warranted regardless of patch status.

CVE-2026-10520 (Ivanti Sentry, formerly MobileIron Sentry) rounds out this pre-auth trio with OS command injection enabling root-level remote code execution. Ivanti products have been a sustained focus of sophisticated threat actors since 2024, and Sentry's role as a mobile device management gateway makes it an exceptionally attractive pivot point into enterprise mobile infrastructure. The deadline was June 14 — eight days overdue. Any Ivanti Sentry instance exposed to the internet without confirmed patching should be treated as a priority incident, not a compliance task. Pull logs, rotate certificates, and verify mobile device enrollments for anomalous activity.

Infrastructure and Platform Compromise: SD-WAN, Shared Hosting, and CMS Attack Chains

A second thematic cluster targets network management planes, hosting infrastructure, and content management systems — environments where a single compromised component can yield lateral movement across tenant boundaries or downstream systems.

CVE-2026-20262 and CVE-2026-20245 both affect Cisco Catalyst SD-WAN Manager, and their co-presence in the KEV catalog within the same week is a significant signal. CVE-2026-20262 is a path traversal allowing an authenticated remote attacker to overwrite any file on the filesystem — a post-authentication persistence mechanism that pairs naturally with credential theft or insider threat scenarios. CVE-2026-20245 enables an authenticated local attacker to execute arbitrary commands as root via a crafted file. Both carry a June 23 deadline, making tomorrow the operational forcing function. Organizations running SD-WAN Manager should treat these as a combined attack chain: initial access via stolen credentials escalating to root persistence. Audit privileged SD-WAN Manager accounts immediately and review recent file creation events in management plane logs.

CVE-2026-54420 (LiteSpeed cPanel Plugin) targets a specific but widely deployed environment: shared hosting servers running CloudLinux and CageFS. The symlink-following vulnerability allows a user with FTP or web shell access to escape tenant isolation — a critical threat model for managed hosting providers and any organization co-tenanting on shared infrastructure. The deadline was June 18 and is now past. Hosting administrators should audit all active FTP accounts and verify CageFS integrity. If you are a tenant on shared hosting and cannot confirm your provider has patched, consider migrating sensitive workloads to isolated environments.

CVE-2026-48907 (Widget Factory Joomla Content Editor) enables unauthenticated users to create editor profiles and upload PHP code — effectively an unauthenticated webshell deployment path on Joomla installations. The deadline was June 19. This vulnerability is particularly dangerous in unmanaged or legacy Joomla environments where plugin update cadences lag behind core CMS patching. Immediately audit your Joomla plugin inventory, disable the Joomla Content Editor plugin if patching cannot be confirmed, and scan web-accessible directories for recently created or modified PHP files.

Deadline Watch: Browser Engine Exposure Closing Tomorrow

CVE-2026-11645 (Google Chromium V8) deserves focused attention as the June 23 deadline arrives tomorrow. An out-of-bounds read/write in the V8 engine allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page — affecting Chrome, Microsoft Edge, Opera, and any Chromium-derived browser. The browser supply chain dimension is significant: one malicious page can target users across multiple browser brands simultaneously. Endpoint teams should confirm auto-update policies have pushed the latest Chromium-based browser versions across the fleet, with particular attention to managed endpoints where auto-update may be disabled. SOC teams should flag any browser version strings predating the patch in endpoint telemetry as a detection priority.

Summary Deadline Table

| CVE | Vendor / Product | Deadline | Status | |---|---|---|---| | CVE-2026-10520 | Ivanti Sentry | June 14 | 8 days overdue | | CVE-2026-35273 | Oracle PeopleSoft | June 15 | 7 days overdue | | CVE-2026-54420 | LiteSpeed cPanel Plugin | June 18 | 4 days overdue | | CVE-2026-48907 | Widget Factory Joomla CE | June 19 | 3 days overdue | | CVE-2026-20253 | Splunk Enterprise | June 21 | 1 day overdue | | CVE-2026-11645 | Google Chromium V8 | June 23 | Due tomorrow | | CVE-2026-20262 | Cisco SD-WAN Manager | June 29 | 7 days remaining | | CVE-2026-20245 | Cisco SD-WAN Manager | June 23 | Due tomorrow |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Ivanti Security Advisories · Oracle Critical Patch Update · Splunk Security Advisories · Google Chrome Releases

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.digitaltrends.comJun 22

Hackers leak facial recognition records tied to millions of Madison Square Garden visitors

And the more comprehensive those records become, the more valuable they are to cybercriminals. Hacker Shutterstock / Shutterstock. The breach also ...

https://www.securityweek.comJun 22

Microsoft Defender Zero-Day RoguePlanet Disclosed and Actively Exploited

A Windows zero-day exploit called RoguePlanet targeting Microsoft Defender was publicly released, allowing local privilege escalation by exploiting a ...

https://www.ajc.comJun 21

Systems restored after data breach in city of Acworth, officials say

A cybersecurity breach in the city of Acworth is still under investigation, but systems and services have been fully restored, officials said.

https://techcrunch.comJun 21

When the Trump administration cracks down on Anthropic, who benefits? - TechCrunch

... cybersecurity capabilities from network defenders in the U.S.”. And we wondered whether this could all end up being good publicity for Anthropic ....

https://www.actionnewsjax.comJun 22

Why physical security is just as important as cybersecurity - Action News Jax

In fact, many cybersecurity vulnerabilities begin with physical access to people, devices, facilities, or sensitive information. There shouldn't be a ...

https://industrialcyber.coFeb 9

Volt Typhoon's targeting of US infrastructure signals disruptive intent beyond espionage

Analysis notes that Volt Typhoon's targeting and use of 'living off the land' tradecraft has redrawn the boundary for acceptable state behavior in cyb...

https://www.crossroadstoday.comJun 21

Hackers access personal info of Texas hunters and fishers in security incident | News

Hackers may have accessed data from more than 3 million hunting and fishing license holders ... The department said driver's license numbers, passport...

https://mashable.comJun 21

Older iPhones are vulnerable to a flaw Apple likely can't fix - Mashable

A cybersecurity firm discovered an unfixable flaw with some iPhone and Apple device models.


Updated daily