CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — June 15, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leadership Reporting Period: June 5–12, 2026 | As of: June 15, 2026
Deadline Watch: Authentication Failures on Critical Perimeter Infrastructure
Three of this week's entries represent the most operationally urgent threat cluster: unauthenticated attackers gaining full system control through broken or absent authentication on internet-facing gateways and enterprise platforms.
CVE-2026-50751 (Check Point Security Gateway) carried a patch deadline of June 11 — four days ago — and remains the most immediately concerning entry in this batch. The vulnerability exploits a flaw in IKEv1 key exchange, allowing a remote, unauthenticated attacker to establish a valid remote access VPN session without credentials. This is not a privilege escalation chain; it is direct network access into environments that depend on VPN as a perimeter control. Organizations still running unpatched Check Point Security Gateways should treat all VPN session logs since early June as potentially compromised, rotate associated credentials, and segment any resources reachable via remote access VPN pending full remediation.
CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) shares similar severity geometry. A missing authentication control on a critical function allows unauthenticated attackers to achieve full platform takeover. The patch deadline was today, June 15, under BOD 26-04, meaning federal agencies and contractors are now at or past the compliance threshold. PeopleSoft environments frequently host HR, payroll, and financial data for large agencies — the blast radius of a takeover extends well beyond the application tier. If patching cannot be completed immediately, restrict external access to the PeopleSoft application server, enforce network-layer controls, and initiate forensic triage per CISA's BOD 26-04 Forensics Triage Requirements before assuming the environment is clean.
CVE-2026-10520 (Ivanti Sentry) rounds out this cluster. The OS command injection flaw enables root-level remote code execution by unauthenticated remote users — effectively the highest possible impact without any credential requirement. Ivanti products have been persistent KEV fixtures, and Sentry's role as a mobile device management gateway makes it a high-value pivot point. The patch deadline of June 14 is also now past. Treat any internet-exposed Sentry instance as potentially compromised, pull device management certificates, and review enrolled device trust chains.
Network Fabric at Risk: SD-WAN, EOS, and Lateral Movement Enablement
Two infrastructure-layer vulnerabilities this period target the routing and switching fabric that underpins enterprise and carrier networks, compounding risk for organizations that rely on software-defined networking or cloud-managed WAN.
CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) involves an improper output encoding flaw that allows an authenticated local attacker to execute commands as root via a crafted file. While the local authentication requirement reduces remote exploitation surface, SD-WAN Manager nodes are frequently administered by third-party MSPs and contractors — broadening the pool of principals who could abuse this. In a compromised MSP scenario, this becomes a supply-chain lever. Patch deadline is June 23; prioritize patching on any SD-WAN Manager node accessible to external administrators or shared service accounts.
CVE-2026-7473 (Arista Extensible Operating System) is technically subtle but strategically significant. Arista EOS incorrectly decapsulates and forwards tunneled packets with destination IPs matching the device's own decapsulation configuration. This incomplete comparison logic can be abused to inject traffic through segmentation boundaries that operators believe are enforced. In data center and cloud-on-ramp environments where Arista EOS underpins micro-segmentation, this is a policy bypass, not merely a routing anomaly. Deadline is also June 23. Until patched, audit tunnel decapsulation configurations and validate that traffic inspection controls sit out-of-band from affected switching paths.
Expanding Attack Surface: Browser Engines, AI Middleware, and File Transfer Services
This week's catalog also captures three increasingly common target categories: end-user browser engines exploited through crafted content, AI/LLM infrastructure lacking hardened privilege models, and file transfer services used as initial access footholds.
CVE-2026-11645 (Google Chromium V8) is a sandbox-escaping out-of-bounds read/write exploitable via a crafted HTML page. Because V8 underpins Chrome, Edge, and Opera, the effective exposed population is nearly universal. Deadline is June 23. Browser patching should be handled through automated update enforcement — if your organization relies on manual browser patching cycles, that process is already inadequate for this threat class. Verify that Chrome and Edge fleet versions are at or above the vendor's remediation build via endpoint management tooling.
CVE-2026-42271 (BerriAI LiteLLM) is a landmark entry: CISA's formal acknowledgment that AI gateway middleware is now active exploitation terrain. Any authenticated user — including low-privilege internal API key holders — can inject commands and execute arbitrary code on the host. LiteLLM is widely deployed as a unified proxy layer over multiple LLM providers in enterprise AI platforms. The threat model here includes insider risk and compromised API keys. Patch by June 22, audit all issued API keys, and enforce least-privilege key scoping immediately. Do not assume that internal-only deployments are safe; lateral movement from adjacent compromised services is a realistic vector.
CVE-2026-28318 (SolarWinds Serv-U) demonstrates that denial-of-service primitives earn KEV status when they are unauthenticated and reliably reproducible. A crafted POST using Content-Encoding: deflate crashes the Serv-U service without any credentials. Beyond availability impact, service crashes can disrupt audit logging, create detection blind spots, and precede follow-on exploitation. Deadline is June 19. SolarWinds Serv-U has appeared in KEV previously in contexts far more severe; treat any exposure of this service to untrusted networks as unacceptable until patched.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Oracle Security Alerts · Ivanti Security Advisories · Google Chrome Releases · Cisco Security Advisories · Arista Security Advisories · Check Point Security Advisories · SolarWinds Security Advisories · BerriAI LiteLLM GitHub
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
AUR Supply Chain Attack: 400+ Arch Packages Backdoored with Rootkit and Infostealer
An AUR supply chain attack compromised over 400 Arch Linux packages starting June 11, 2026, planting a Rust-based credential stealer and an eBPF rootk...
Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation
Palo Alto Networks warned that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway, is being actively exp...
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
ShinyHunters successfully exploited a critical Oracle PeopleSoft zero-day vulnerability to compromise over 100 organizations across 300 vulnerable ins...
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Google's Mandiant team confirmed that ShinyHunters actively exploited the Oracle PeopleSoft zero-day (CVE-2026-35273) between May 27 and June 9, 2026,...
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
A new class of attack called Agentjacking exploits AI coding agents by injecting malicious code through fake error reports in Sentry, allowing arbitra...
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
"Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events." Cybersecurity. The company has ...
Chrome V8 JavaScript Engine Zero-Day (CVE-2026-11645) Under Active Wild Exploitation
Google confirmed that CVE-2026-11645, an out-of-bounds memory access vulnerability in Chrome's V8 JavaScript engine, is being actively exploited in th...
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ShinyHunters exploited a critical unpatched flaw in Oracle PeopleSoft to breach over 100 organizations, primarily targeting universities, stealing dat...
Updated daily
