Monthly Vuln Summary 2026-06 (23)
In-the-Wild CVE Review · 2026-06
23 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2026-48558 —
0.0— SimpleHelp SimpleHelp — SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accep… [KEV] - CVE-2026-12569 —
0.0— PTC Windchill and FlexPLM — PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request … [KEV] [RANSOMWARE] - CVE-2026-20230 —
0.0— Cisco Unified Communications Manager — Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) … [KEV] - CVE-2025-67038 —
0.0— Lantronix EDS5000 — Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed wit… [KEV] - CVE-2026-34910 —
0.0— Ubiquiti UniFi OS — Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. [KEV] - CVE-2026-34909 —
0.0— Ubiquiti UniFi OS — Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be mani… [KEV] - CVE-2026-34908 —
0.0— Ubiquiti UniFi OS — Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. [KEV] - CVE-2026-20253 —
0.0— Splunk Enterprise — Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a Po… [KEV] - CVE-2026-48907 —
0.0— Widget Factory Joomla Content Editor ** — Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profile… [KEV]** - CVE-2026-54420 —
0.0— LiteSpeed cPanel Plugin — LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running Clou… [KEV] - CVE-2026-20262 —
0.0— Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the … [KEV] - CVE-2026-35273 —
0.0— Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of P… [KEV] [RANSOMWARE] - CVE-2026-10520 —
0.0— Ivanti Sentry — Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code… [KEV] - CVE-2026-11645 —
0.0— Google Chromium V8 — Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerabil… [KEV] - CVE-2026-7473 —
0.0— Arista Extensible Operating System — Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected … [KEV] - CVE-2026-20245 —
0.0— Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local atta… [KEV] - CVE-2026-42271 —
0.0— BerriAI LiteLLM — BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands… [KEV] - CVE-2026-50751 —
0.0— Check Point Security Gateway — Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authenticati… [KEV] [RANSOMWARE] - CVE-2026-28318 —
0.0— SolarWinds Serv-U — SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Se… [KEV] - CVE-2026-45247 —
0.0— Mirasvit Mirasvit Full Page Cache Warmer — Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying … [KEV] - CVE-2022-0492 —
0.0— Linux Kernel — Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. [KEV] - CVE-2025-48595 —
0.0— Android Framework — Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. [KEV] - CVE-2024-21182 —
0.0— Oracle WebLogic Server — Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.