This month: 24 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-48558
SimpleHelp · SimpleHelp
SimpleHelp Authentication Bypass Vulnerability
Detected Jun 29 · 3-day patch deadline
CVE-2026-12569
PTC · Windchill and FlexPLM
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Detected Jun 25 · 3-day patch deadline
CVE-2026-20230
Cisco · Unified Communications Manager
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Detected Jun 25 · 3-day patch deadline

KEV Intelligence Brief — June 30, 2026

Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Reporting Period: June 18–29, 2026 | 8 CVEs Covered

Unauthenticated Entry Points: The Most Urgent Threat Cluster

The most consequential pattern across this reporting period is a concentration of vulnerabilities that require zero authentication to exploit, several of which enable remote code execution or full system compromise directly from the internet. These demand immediate triage regardless of patching status.

CVE-2026-48558 (SimpleHelp) is the most time-sensitive entry in this brief, added June 29 with a patch deadline of July 2 — two days from today. SimpleHelp's OIDC authentication flow accepts identity tokens without verifying cryptographic signatures, meaning an attacker can forge a token with arbitrary claims and land a fully authenticated technician session. In environments where MFA is layered on top of OIDC, that control is also bypassed. SimpleHelp is widely deployed by MSPs and IT support teams as a remote access tool — the same attack surface that has historically attracted ransomware operators. If your organization uses SimpleHelp with OIDC configured, treat this as an active incident posture: isolate the server from the public internet, rotate all technician credentials and API keys, audit session logs for anomalous logins, and apply the vendor patch before Thursday. Do not wait on change windows.

CVE-2026-12569 (PTC Windchill and FlexPLM) carries a patch deadline of June 28 — already overdue. An unauthenticated remote attacker can send a malformed request to achieve arbitrary code execution. Windchill and FlexPLM are product lifecycle management platforms used heavily by defense industrial base contractors and manufacturing supply chains. Internet exposure of these systems is not uncommon in enterprise environments where remote supplier access is provisioned. If you have not patched, your BOD 26-04 obligation is in breach. Immediately assess internet accessibility, apply compensating controls such as WAF rules and network segmentation, and escalate patching with emergency change authority if needed.

CVE-2026-20253 (Splunk Enterprise) was added June 18 with a deadline of June 21 — nine days overdue. A missing authentication control on a PostgreSQL sidecar service endpoint allows unauthenticated users to create or truncate arbitrary files. In a SIEM context, this is particularly dangerous: an attacker who can truncate log files or configuration data on your Splunk infrastructure can blind your detection capability while operating freely elsewhere. Splunk operators who have not patched should immediately firewall the sidecar service port at the host and network level, verify file integrity on the Splunk instance, and treat any anomalous file changes in the past month as potentially adversary-driven.

Network Infrastructure Trifecta: Ubiquiti UniFi Under Active Threat

Three simultaneous KEV additions against Ubiquiti UniFi OS — CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 — were all added June 23 with deadlines of June 26, now four days overdue. The combination of vulnerabilities here tells a coherent exploitation story that security teams should read as a probable chained attack path.

CVE-2026-34908 is an improper access control flaw enabling unauthorized system changes from the local network. CVE-2026-34909 is a path traversal vulnerability exposing underlying system files that can be manipulated to compromise accounts. CVE-2026-34910 is an improper input validation flaw enabling command injection. Individually, each is serious. Together, they form a plausible sequence: gain a foothold via access control bypass, traverse to credential material, then execute arbitrary commands. UniFi OS underpins a broad range of Ubiquiti network devices popular in mid-market enterprises, branch offices, and government facilities. Network-adjacent threat actors — including those with lateral movement footholds inside a perimeter — can exploit all three without external internet access. Patch UniFi OS to the vendor's current release immediately, audit device management plane exposure, and review recent configuration change logs for unauthorized activity.

Critical Infrastructure and Communications: Cisco UCM and Lantronix EDS5000

Two KEV entries this period target operational and communications infrastructure with high-impact primitives.

CVE-2026-20230 (Cisco Unified Communications Manager) was added June 25 with a deadline of June 28, now overdue. This SSRF vulnerability allows an unauthenticated attacker to write arbitrary files to the underlying OS, creating a reliable path to root-level privilege escalation. Cisco UCM and UCM SME are deployed broadly across federal agencies and large enterprises as core telephony infrastructure. An SSRF-to-file-write chain on an unauthenticated endpoint is a high-confidence pre-exploitation primitive — defenders should assume adversaries are already probing. Apply Cisco's patch, restrict web management interface access to trusted IP ranges, and review recent file system changes on affected hosts.

CVE-2025-67038 (Lantronix EDS5000) added June 23 with a deadline of June 26 addresses OS command injection through the username parameter, executed with root privileges. The EDS5000 is a device server used in OT and industrial environments to network-enable serial devices. Root-level code injection on OT-adjacent infrastructure is a critical-severity finding in any industrial control system context. If a vendor patch is unavailable or cannot be applied in the current operational window, isolate the device behind an OT-specific network segment with strict ACLs, disable any internet-facing management interfaces, and initiate vendor contact for compensating guidance per BOD 26-04.

Deadline Summary

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-48558 | SimpleHelp | July 2, 2026 | ⚠ 2 days remaining | | CVE-2026-12569 | PTC Windchill/FlexPLM | June 28, 2026 | 🔴 Overdue | | CVE-2026-20230 | Cisco UCM | June 28, 2026 | 🔴 Overdue | | CVE-2025-67038 | Lantronix EDS5000 | June 26, 2026 | 🔴 Overdue | | CVE-2026-34908/09/10 | Ubiquiti UniFi OS | June 26, 2026 | 🔴 Overdue | | CVE-2026-20253 | Splunk Enterprise | June 21, 2026 | 🔴 Overdue |

All overdue items represent active BOD 26-04 compliance failures for federal agencies and contractors operating under that directive. Prioritize in order of internet exposure and authentication requirement — unauthenticated RCE and authentication bypass vulnerabilities on internet-accessible systems should be treated as potential active compromises until forensic triage confirms otherwise.

Sources: CISA KEV Catalog · Cisco Security Advisories · PTC Product Security · Ubiquiti Security Advisories · Splunk Security Advisories · SimpleHelp Security Notices · Lantronix Support · CISA BOD 26-04

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.helpnetsecurity.comJun 5

Cisco Catalyst SD-WAN Manager Zero-Day Privilege Escalation Being Exploited (CVE-2026-20245)

An unpatched zero-day privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited by attackers in the wild.

https://thehackernews.comJun 29

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

It never enforced an upper bound. Cybersecurity. The size calculation adds packet_length to a couple of small values using 32-bit arithmetic, so a ...

https://www.justice.govJun 27

Former U.S. National Security Advisor John R. Bolton, II Pleads Guilty to Violating the Espionage Act

... hacked by a cyber actor allegedly linked to the Islamic Republic of Iran. ... Bolton reported that hack to law enforcement but did not tell the .....

https://thehill.comJun 27

Secret Service didn't secure mobile devices, putting leaders at risk, report says - The Hill

Secret Service agents' reliance on personal devices for official business exposes them to hacking risks, says government watchdog report.

https://www.bankinfosecurity.comJun 27

A Hack Too Far? Report Ties Russia to Jaguar Land Rover Hit - BankInfoSecurity

Suggestions that the Kremlin orchestrated the disruptive hack attack against British automotive giant Jaguar Land Rover raise the question of how ...

https://www.nytimes.comJun 26

A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy - The New York Times

Last year, hackers burrowed into the computer systems of Jaguar Land Rover, a crown jewel of British manufacturing. It was a devastating attack ...

https://abcnews.comJun 26

Iranian national sought by US on hacking charges arrested in Montenegro - ABC News

Montenegrin police say they have arrested an Iranian national who is wanted by the United States for mass hacking attacks that caused damage of ...

https://thehackernews.comJun 26

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware ...


Updated daily