Cyber Threats Daily — 2026-07-11
TITLE: KEV Deluge: 39 New Actively-Exploited CVEs, Most Deadlines Already Blown — Joomla Plugins, Cisco, PAN-OS, Ransomware Ties
---
Lead: Remediation clock already expired on most of today's batch
CISA pushed 39 new KEV entries in this pull, and the math is ugly: only CVE-2026-56291 (Balbooa Forms) and CVE-2026-48939 (iCagenda) still have live deadlines — both due 2026-07-13, giving federal agencies two days to patch unrestricted file-upload flaws in these Joomla/WordPress form extensions. Every other entry in this batch has a remediation date that has already passed as of today (2026-07-11), meaning any FCEB agency still running unpatched instances is out of compliance right now.
Ransomware-linked — patch first
Four items carry CISA's "known ransomware use" tag and deserve top priority regardless of deadline status:
- CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools missing-authentication flaw, deadline 2026-06-15 (nearly a month overdue), actively leveraged by ransomware crews to bypass auth entirely.
- CVE-2026-50751 — Check Point Security Gateway improper-authentication bug, due 2026-06-11, also ransomware-linked; gateway compromise here is a direct path to network-wide lateral movement.
- CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) — both embedded-malicious-code/supply-chain issues in developer tooling, due 2026-06-10, showing ransomware operators are now targeting dev pipelines, not just edge appliances.
Network & remote-access infrastructure
A cluster of perimeter and remote-management products round out the exploited list: CVE-2026-20230, CVE-2026-20262, and CVE-2026-20245 hit Cisco Unified Communications Manager and Catalyst SD-WAN Manager (SSRF, path traversal, output-encoding flaws) with deadlines from 06-15 to 06-29. CVE-2026-0257 is a Palo Alto Networks PAN-OS auth-bypass (due 06-01), and CVE-2026-10520 is an Ivanti Sentry OS command-injection bug (due 06-14) — both classic initial-access vectors for follow-on ransomware. CVE-2026-48558, a SimpleHelp authentication bypass (due 07-02, now overdue), is especially concerning given SimpleHelp's history as an RMM tool abused for ransomware staging. Also overdue: CVE-2026-28318 (SolarWinds Serv-U resource exhaustion, due 06-19) and CVE-2026-20253 (Splunk Enterprise missing authentication, due 06-21).
Joomla/CMS plugin file-upload wave
Five of the newest additions are Joomla-ecosystem extensions with unrestricted file-upload or access-control weaknesses: CVE-2026-56291 (Balbooa Forms), CVE-2026-48939 (iCagenda), CVE-2026-48908 (JoomShaper SP Page Builder), CVE-2026-56290 (Joomlack Page Builder), and CVE-2026-48907 (Widget Factory Joomla Content Editor). These are near-identical in impact — attacker-controlled file uploads leading to remote code execution — and their clustering suggests active mass-scanning against Joomla sites. Only the first two retain unexpired deadlines; the rest were due 06-10 to 07-10.
Enterprise apps and AI/dev tooling
CVE-2026-48282 is a path-traversal bug in Adobe ColdFusion (due 07-10, just missed), and CVE-2026-45659 is a deserialization flaw in Microsoft SharePoint Server (due 07-04) — both high-value targets for web-shell drops. On the AI-tooling side, CVE-2026-55255 (Langflow authorization bypass via user-controlled key) and its sibling CVE-2025-34291 (Langflow origin validation error) both had 07-10 and 06-04 deadlines respectively, while CVE-2026-42271 (BerriAI LiteLLM command injection, due 06-22) continues the trend of LLM-orchestration frameworks landing in KEV.
Networking gear and legacy code still under fire
Ubiquiti UniFi OS picked up three simultaneous KEV entries — CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 (input validation, path traversal, access control) — all due 06-26. Older infrastructure isn't spared either: CVE-2025-67038 hits Lantronix EDS5000 serial-to-network devices, and CVE-2026-7473 affects Arista EOS.
Notably, CISA also re-flagged legacy bugs still seeing active exploitation: CVE-2022-0492 (Linux kernel improper authentication, cgroups-related), CVE-2025-48595 (Android Framework integer overflow), CVE-2024-21182 (Oracle WebLogic Server), and two genuinely ancient Windows-era flaws — CVE-2008-4250 (Windows buffer overflow) and CVE-2009-1537 (DirectX NULL-byte overwrite) — a reminder that unpatched legacy systems remain viable targets nearly two decades later.
Bottom line
With the vast majority of this batch already past its federal remediation window, treat this less as a "new deadlines" alert and more as a compliance audit trigger — confirm patch status on Cisco SD-WAN/UCM, PAN-OS, Ivanti Sentry, SimpleHelp, and the Joomla plugin cluster immediately, and prioritize the two ransomware-tagged entries (PeopleSoft, Check Point) if not already remediated.
