CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — June 28, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leadership Reporting Period: June 16–25, 2026 | Today's Date: Sunday, June 28, 2026
Eight vulnerabilities added to CISA's KEV catalog over the past twelve days reflect three distinct threat themes: unauthenticated remote code execution targeting enterprise infrastructure, a coordinated wave of exploitation against widely deployed network operating systems, and opportunistic compromise of internet-facing content and communications platforms. Several deadlines have already passed as of today — teams that have not yet acted are operating in a known-exploited, out-of-compliance posture.
DEADLINE BREACHED: Unauthenticated RCE Across Enterprise Infrastructure
The highest-severity cluster this cycle centers on vulnerabilities where attackers require no credentials whatsoever. Three entries — each carrying a patch deadline that has now passed — fall into this category, and all three should be treated as actively hostile environments until remediation is confirmed.
CVE-2026-12569 (PTC Windchill and FlexPLM, deadline: today, June 28) represents an acute risk for defense industrial base contractors and manufacturing organizations. Windchill is a product lifecycle management platform deeply embedded in aerospace, defense, and automotive supply chains. An unauthenticated remote attacker can send a malicious network request to achieve arbitrary code execution — no foothold required. If your Windchill or FlexPLM instance has any internet exposure, treat it as compromised pending forensic review. Isolate from external network segments immediately, apply PTC's patch or workaround, and conduct the forensic triage now required under CISA's BOD 26-04 obligations.
CVE-2026-20253 (Splunk Enterprise, deadline: June 21, already overdue) targets a missing authentication check on a PostgreSQL sidecar service endpoint, allowing unauthenticated file creation or truncation. The operational implication is significant: Splunk is often the system of record for security telemetry, meaning successful exploitation can blind or manipulate your detection capability before or during a broader intrusion. Teams running Splunk Enterprise should confirm the patch is applied, audit the PostgreSQL sidecar service for unauthorized file activity, and verify log integrity going back at least to June 18 when this entry was added to KEV.
CVE-2026-48907 (Widget Factory Joomla Content Editor, deadline: June 19, overdue) allows unauthenticated users to create new editor profiles as a vehicle for uploading and executing arbitrary PHP code. Joomla-based public-facing websites — common in government, education, and nonprofit sectors — are the target surface. If this plugin is present and unpatched, assume webshell deployment is possible and conduct file integrity checks against the web root, particularly in directories writable by the CMS.
All three of these deadlines have passed. BOD 26-04 compliance requires that federal agencies and covered contractors have already acted. If patching is not feasible, CISA's guidance is unambiguous: discontinue use or enforce network-level isolation.
Network Infrastructure Under Active Pressure: UniFi OS and Cisco UCM
The second thematic cluster targets network and communications infrastructure, where exploitation can provide persistent access across an environment rather than to a single host.
Ubiquiti UniFi OS accounts for three simultaneous KEV entries — CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), and CVE-2026-34910 (command injection) — all added June 23 with a deadline of June 26, now overdue. This cluster is significant precisely because of its composition: three distinct vulnerability classes affecting the same OS. An attacker with network access can chain access control bypass into path traversal to retrieve sensitive system files, then leverage command injection to achieve root-level execution. UniFi OS underpins routers, switches, and wireless access points across SMB and enterprise environments, including many federal facility networks. Patch to the latest UniFi OS release immediately. Where patching cannot be completed, place management interfaces behind a dedicated, access-controlled management VLAN and disable remote administration over untrusted networks.
CVE-2026-20230 (Cisco Unified Communications Manager and Unified CM SME, deadline: June 28, today) is a server-side request forgery vulnerability that allows an unauthenticated attacker to write arbitrary files to the underlying operating system — files that can then be leveraged to escalate to root. Cisco UCM and UCM SME are foundational to enterprise telephony and collaboration infrastructure, and root-level compromise of these platforms can expose call records, voicemail, and internal network topology. Apply Cisco's advisory patch now, enforce network perimeter controls so the UCM administrative interface is not reachable from untrusted networks, and rotate administrative credentials after patching as a standard post-incident hygiene measure.
OT and Serial Device Exposure: Lantronix EDS5000
CVE-2025-67038 (Lantronix EDS5000, deadline: June 26, overdue) is the entry most likely to be underestimated in a standard IT-centric patch cycle. The EDS5000 is a serial-to-Ethernet device server used extensively in operational technology environments to bridge legacy serial equipment to IP networks — found in industrial control systems, medical device networks, and critical infrastructure. The vulnerability allows OS command injection via the username parameter, executing with root privileges. This is not a theoretical escalation path; it is a direct root shell. OT teams must inventory EDS5000 deployments, apply available firmware, and where patching is impractical, enforce strict network segmentation ensuring these devices are reachable only from authorized engineering workstations. Internet exposure of any EDS5000 device should be treated as a critical incident.
Bottom Line for Operations
Every entry in this cycle involves either unauthenticated access or a low-barrier authenticated path to high-impact outcomes. Four of the eight deadlines were in the past week and are now overdue. Teams must confirm patch status, conduct forensic triage per BOD 26-04 where exploitation cannot be ruled out, and document remediation decisions for compliance records.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory – Unified CM SSRF · PTC Security Bulletin – Windchill · Ubiquiti Security Advisory – UniFi OS · Splunk Security Advisory · Lantronix Product Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Former U.S. National Security Advisor John R. Bolton, II Pleads Guilty to Violating the Espionage Act
... hacked by a cyber actor allegedly linked to the Islamic Republic of Iran. ... Bolton reported that hack to law enforcement but did not tell the .....
Secret Service didn't secure mobile devices, putting leaders at risk, report says - The Hill
Secret Service agents' reliance on personal devices for official business exposes them to hacking risks, says government watchdog report.
A Hack Too Far? Report Ties Russia to Jaguar Land Rover Hit - BankInfoSecurity
Suggestions that the Kremlin orchestrated the disruptive hack attack against British automotive giant Jaguar Land Rover raise the question of how ...
A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy - The New York Times
Last year, hackers burrowed into the computer systems of Jaguar Land Rover, a crown jewel of British manufacturing. It was a devastating attack ...
Iranian national sought by US on hacking charges arrested in Montenegro - ABC News
Montenegrin police say they have arrested an Iranian national who is wanted by the United States for mass hacking attacks that caused damage of ...
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware ...
White House State Infrastructure Cybersecurity Initiative Faces Implementation Delays
The Trump administration's effort to help states implement innovative cybersecurity defenses remains stalled with most states still waiting to partici...
CISA Issues Emergency Directive for Check Point VPN Zero-Day Exploited by Ransomware Groups
CISA issued an emergency directive to patch critical Check Point VPN zero-day CVE-2026-50751 being actively exploited by ransomware groups via unauthe...
Updated daily
