This month: 16 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-48907
Widget Factory · Joomla Content Editor
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Detected Jun 16 · 3-day patch deadline
CVE-2026-54420
LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Detected Jun 15 · 3-day patch deadline
CVE-2026-35273
Oracle · PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Detected Jun 12 · 3-day patch deadline

KEV Intelligence Brief — June 18, 2026

Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Reporting Period: CVEs added to CISA KEV June 9–16, 2026

Deadline Watch: Critical Expirations Are Here and Past Due

Three patch deadlines from this cycle have already passed or expire today, and a fourth expires tomorrow. Organizations still exposed should treat remediation as an active incident, not a compliance checkbox.

CVE-2026-10520 (Ivanti Sentry) carried a deadline of June 14 — four days ago. This OS command injection flaw requires no authentication and delivers root-level remote code execution. Ivanti Sentry functions as a mobile device management gateway, meaning exploitation doesn't just compromise the appliance — it positions an attacker to intercept or manipulate managed device traffic across the enterprise. If you have not patched, isolate the appliance from public ingress immediately, rotate any certificates or credentials Sentry brokers, and initiate forensic triage per CISA's BOD 26-04 requirements before applying the patch.

CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) deadline passed June 15. This missing-authentication vulnerability allows unauthenticated full takeover of PeopleSoft — an ERP platform that routinely holds payroll data, HR records, and financials for large federal agencies and universities. Unauthenticated takeover of a system at this tier is a maximum-severity operational event. If you cannot confirm patching, restrict network access to the PeopleSoft portal to known IP ranges and audit authentication logs for anomalous access patterns going back at least 30 days.

CVE-2026-54420 (LiteSpeed cPanel Plugin) expired yesterday, June 18. This UNIX symlink-following vulnerability targets shared hosting environments running CloudLinux/CageFS — architectures specifically designed to isolate tenants from one another. Successful exploitation by a user with FTP or web shell access breaks that isolation boundary entirely, enabling cross-tenant data access. Hosting providers and managed service operators should treat this as an infrastructure-tier risk, not a single-tenant issue. Audit all cPanel plugin versions across your fleet and verify CageFS integrity after patching.

CVE-2026-48907 (Widget Factory Joomla Content Editor) carries a deadline of tomorrow, June 19. This improper access control vulnerability allows unauthenticated users to create new editor profiles and upload executable PHP — effectively handing any anonymous visitor a webshell. PHP upload primitives on CMS platforms are well-understood attacker workflows; exploitation does not require sophistication. If patching by tomorrow is not achievable, disable the plugin entirely and review server logs for unexpected PHP file creation or execution events, particularly in upload and editor-profile directories.

Network Infrastructure Under Coordinated Pressure: Cisco SD-WAN and Arista EOS

Two separate Cisco Catalyst SD-WAN Manager vulnerabilities entered the KEV catalog within six days of each other, and they compound one another in a realistic attack chain.

CVE-2026-20245 (added June 9, deadline June 23) is an improper encoding or escaping vulnerability allowing an authenticated local attacker to execute arbitrary commands as root via a crafted file. CVE-2026-20262 (added June 15, deadline June 29) is a path traversal flaw that lets an authenticated remote attacker create or overwrite any file on the system. Neither requires authentication escalation if an attacker already holds low-privilege credentials — and the path traversal flaw could be used to stage the malicious file that CVE-2026-20245 then executes. Organizations managing SD-WAN through a centralized vManage console should assume that a single set of compromised credentials can translate to full infrastructure control. Rotate SD-WAN Manager credentials now, enforce MFA on the management interface, and restrict console access to jump hosts or dedicated management VLANs. Both carry June 23 and June 29 deadlines, but given the chaining risk, treat the earlier deadline as controlling.

CVE-2026-7473 (Arista Extensible Operating System), also with a June 23 deadline, introduces a different but equally concerning network-layer risk. The incomplete comparison flaw causes Arista switches to incorrectly decapsulate and forward tunneled packets whose destination IP matches the switch's own decapsulation address. In practice, this can allow an attacker to inject unexpected traffic into protected network segments — a primitive that supports lateral movement and network segmentation bypass. Data center operators and federal network teams running Arista EOS should audit tunnel decapsulation configurations and apply the vendor patch before June 23.

Browser Engine and CMS Exposure: Supply-Chain Surface Area at Scale

CVE-2026-11645 (Google Chromium V8), added June 9 with a June 23 deadline, is an out-of-bounds read and write vulnerability enabling arbitrary code execution inside a sandbox via a crafted HTML page. The scope extends beyond Chrome — any browser or application embedding the Chromium engine, including Microsoft Edge and Opera, is potentially affected. For federal agencies and contractors operating under BOD 26-04, browser patching is non-negotiable. Push Chrome and Edge updates via enterprise management tooling immediately; do not wait for users to self-update. Verify that auto-update mechanisms have not been disabled by policy or prior misconfiguration.

Taken alongside CVE-2026-48907 — the Joomla Content Editor webshell primitive — this week's catalog reflects a recurring pattern: attackers are targeting the delivery and rendering layer simultaneously. A compromised Joomla site hosting a malicious page becomes a credible browser exploitation vector when Chromium remains unpatched on visiting endpoints. These two vulnerabilities, from different vendors and product categories, operate as complementary stages in a client-side compromise chain.

Summary Prioritization

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-10520 | Ivanti Sentry | June 14 | Overdue | | CVE-2026-35273 | Oracle PeopleSoft | June 15 | Overdue | | CVE-2026-54420 | LiteSpeed cPanel Plugin | June 18 | Due Today | | CVE-2026-48907 | Widget Factory Joomla CE | June 19 | Due Tomorrow | | CVE-2026-11645 | Google Chromium V8 | June 23 | 5 days | | CVE-2026-20245 | Cisco SD-WAN Manager | June 23 | 5 days | | CVE-2026-7473 | Arista EOS | June 23 | 5 days | | CVE-2026-20262 | Cisco SD-WAN Manager | June 29 | 11 days |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Ivanti Security Advisory Portal · Oracle Critical Patch Update · Arista Security Advisories · Google Chrome Releases · LiteSpeed Technologies Security Notices

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.wsj.comJun 18

How Hackers Found a Back Door Into the American Living Room

Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a global threat

https://www.pv-magazine.comJun 16

The real cybersecurity debate around chinese inverters is only just beginning - PV Magazine

The European Commission's move to restrict funding for projects using high-risk inverter vendors marks a turning point for solar cybersecurity.

https://www.silicon.co.ukJun 16

China-Linked Hackers Stole Data For More Than A Year - Silicon UK

The hackers sought materials related to defence intelligence, military strategy in the Indo-Pacific region, AI, unmanned vehicles, cyber warfare ...

https://thehackernews.comJun 16

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.

https://www.northcountrypublicradio.orgJun 17

Can computer hackers get inside your mind? | NCPR News

On today's show: a whodunit about hackers, 'Cyber Paleontologists', spy-vs-spy protocols, cryptic intelligence leaks, nuclear physics, high-precision ...

https://www.wired.comJun 17

'Dangerous' AI Models Are Coming No Matter What | WIRED

The US government crackdown on Anthropic's Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will ...

https://www.axios.comJun 16

Trump's Anthropic crackdown rattles cyber defenders - Axios

AI researchers and cybersecurity leaders fear the U.S. government is setting a precedent that may discourage American AI companies from building ...

https://thehackernews.comJun 17

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla ...


Updated daily