← Archive
Cyber Threats Daily2026-07-12July 12, 2026

Cyber Threats Daily — 2026-07-12

TITLE: CISA KEV Deluge: Oracle, Check Point Ransomware Exploits Lead 40 New Additions — Multiple Deadlines Already Elapsed

---

Ransomware Actors Actively Exploiting Four Flaws

CISA's KEV catalog flags four vulnerabilities with confirmed ransomware use, and all four remediation windows have already closed. CVE-2026-35273 is a missing-authentication bug in Oracle PeopleSoft Enterprise PeopleTools with a remediation deadline that lapsed 2026-06-15 — treat any unpatched instance as compromised. CVE-2026-50751, an improper-authentication flaw in Check Point Security Gateway, blew past its 2026-06-11 deadline and is a favored ransomware entry point for perimeter appliances. On the software-supply-chain side, CVE-2026-48027 (Nx Console embedded malicious code) and CVE-2026-45321 (TanStack, unspecified) were both due 2026-06-10 — these hit developer tooling directly, so audit build pipelines and CI runners that pulled either package during the exposure window.

Deadline Tomorrow: CMS Plugin Upload Bugs

A cluster of Joomla/CMS unrestricted-file-upload and access-control issues carries a 2026-07-13 deadline — the tightest turnaround in today's batch. CVE-2026-56291 (Balbooa Forms) and CVE-2026-48939 (iCagenda) both allow dangerous file-type uploads; pair them with the already-overdue CVE-2026-48908 (JoomShaper SP Page Builder, due 07-10), CVE-2026-56290 (Joomlack Page Builder, due 07-10), and CVE-2026-48907 (Widget Factory Joomla Content Editor, due 06-19) — the whole family points to active scanning against Joomla extension ecosystems. Patch or disable affected plugins now.

Enterprise Infrastructure — Deadlines Already Blown

Several high-value enterprise targets have overdue KEV deadlines and warrant priority triage regardless of the missed date. CVE-2026-45659 (Microsoft SharePoint Server deserialization, due 07-04) and CVE-2026-48282 (Adobe ColdFusion path traversal, due 07-10) both enable remote code execution on internet-facing servers. CVE-2026-48558 (SimpleHelp authentication bypass, due 07-02) is notable given SimpleHelp's history as a ransomware staging tool. CVE-2026-20253 (Splunk Enterprise missing authentication, due 06-21) and CVE-2026-0257 (Palo Alto Networks PAN-OS authentication bypass, due 06-01) round out the list — PAN-OS auth-bypass bugs have repeatedly been chained for firewall takeover in past campaigns.

Cisco shows up three times: CVE-2026-20230 (Unified Communications Manager SSRF, due 06-28), CVE-2026-20262 (Catalyst SD-WAN Manager directory traversal, due 06-29), and CVE-2026-20245 (Catalyst SD-WAN Manager output-encoding flaw, due 06-23) — SD-WAN Manager is now a two-bug target, so prioritize that platform first.

Edge & Network Devices

Ubiquiti UniFi OS collected three simultaneous KEV entries — CVE-2026-34910 (input validation), CVE-2026-34909 (path traversal), and CVE-2026-34908 (access control) — all due 06-26, suggesting a coordinated exploit chain against UniFi controllers rather than isolated bugs. Separately, CVE-2025-67038 hits Lantronix EDS5000 via code injection (due 06-26) and CVE-2026-7473 affects Arista EOS through a comparison logic flaw (due 06-23) — both are OT/network-adjacent and should be checked against asset inventories even though their deadlines have passed.

Legacy CVEs Resurface — Watch for Renewed Campaigns

CISA re-flagged three aged vulnerabilities this cycle, a strong signal of fresh in-the-wild activity against unpatched legacy systems: CVE-2008-4250 (Windows buffer overflow) and CVE-2009-1537 (DirectX NULL byte overwrite), both due 06-03, alongside CVE-2022-0492 (Linux kernel improper authentication, due 06-05). Organizations still running unsupported Windows builds or old kernel versions should assume active scanning.

Remaining Additions to Track

Rounding out the batch: CVE-2026-12569 (PTC Windchill/FlexPLM input validation, due 06-28), CVE-2026-11645 (Chromium V8 out-of-bounds read/write, due 06-23 — update browsers fleet-wide), CVE-2026-42271 (BerriAI LiteLLM command injection, due 06-22 — relevant to AI infra deployments), CVE-2026-28318 (SolarWinds Serv-U resource exhaustion, due 06-19), CVE-2026-54420 and CVE-2026-48172 (LiteSpeed cPanel plugin symlink-following and privilege escalation, due 06-18 and 05-29 respectively), CVE-2026-9082 (Drupal Core SQL injection, due 05-27), CVE-2025-34291 (Langflow origin validation error, due 06-04 — paired with the newer CVE-2026-55255 Langflow authorization bypass due 07-10, making Langflow a two-CVE priority), CVE-2026-34926 (Trend Micro Apex One directory traversal, due 06-04), CVE-2026-45247 (Mirasvit Full Page Cache Warmer deserialization, due 06-06), CVE-2024-21182 (Oracle WebLogic, due 06-04), CVE-2025-48595 (Android Framework integer overflow, due 06-05), and CVE-2026-8398 (Daemon Tools Lite embedded malicious code, due 05-30).

Bottom line: With today at 2026-07-12, the majority of this batch's federal remediation deadlines have already elapsed — only the Joomla/CMS upload cluster (due 07-13) remains inside its window. Any federal or high-security environment still exposed on the Oracle, Check Point, or Langflow entries should treat this as an active-breach scenario, not a patch backlog.