← Archive
Cyber Threats Daily2026-07-01July 1, 2026

Cyber Threats Daily — 2026-07-01

TITLE: Cyber Threats Daily — SimpleHelp auth bypass hits KEV with 24hr deadline; ransomware crews mining PeopleSoft, Check Point, Nx

---

Top of the Watch

  • CVE-2026-48558 SimpleHelp authentication bypass hit KEV on 2026-06-29 with a remediation deadline of 2026-07-02 — a 72-hour window signaling active exploitation. Federal civilian agencies and MSPs running SimpleHelp remote support should patch or isolate today.
  • Three ransomware-flagged KEV entries dominate the ransomware picture this cycle: CVE-2026-35273 (Oracle PeopleSoft PeopleTools missing auth on a critical function), CVE-2026-50751 (Check Point Security Gateway improper authentication), and CVE-2026-48027 (Nx Console embedded malicious code — a supply-chain compromise of the popular monorepo tooling). CVE-2026-45321 in TanStack also carries the ransomware-use tag. All four had June deadlines that are now past — treat any unpatched instance as presumed-compromised.

Network Edge & Perimeter

  • CVE-2026-0257, a Palo Alto Networks PAN-OS authentication bypass, was KEV-added 2026-05-29 with a 2026-06-01 deadline — one of the tightest windows this cycle, consistent with in-the-wild abuse against management planes. Confirm patch status across all firewalls.
  • Cisco appears three times: CVE-2026-20182 (Catalyst SD-WAN Controller auth bypass), CVE-2026-20262 (Catalyst SD-WAN Manager path traversal), and CVE-2026-20245 (Catalyst SD-WAN Manager output-encoding flaw), plus CVE-2026-20230 SSRF in Unified Communications Manager. SD-WAN operators should assume chained exploitation is plausible given the authN + traversal combo.
  • CVE-2026-7473 in Arista EOS (incomplete comparison logic) and CVE-2026-10520 OS command injection in Ivanti Sentry round out the network-gear additions — Ivanti Sentry in particular remains a high-value target given historical exploitation patterns.
  • Three Ubiquiti UniFi OS bugs landed together on 2026-06-23 (CVE-2026-34908 access control, CVE-2026-34909 path traversal, CVE-2026-34910 input validation), suggesting a single research disclosure or campaign against UniFi controllers.

Server & Enterprise Software

  • CVE-2026-20253 Splunk Enterprise missing authentication on a critical function is the standout data-plane risk of the cycle — an unauthenticated path to a SIEM is a monitoring-blinding scenario. Deadline was 2026-06-21.
  • CVE-2026-12569 hits PTC Windchill and FlexPLM (PLM systems holding IP-crown-jewel engineering data) via improper input validation; deadline 2026-06-28.
  • CVE-2026-42897 (Exchange Server XSS) and two Microsoft Defender flaws (CVE-2026-41091 link-following, CVE-2026-45498 DoS) show attackers continuing to target the security stack itself. Older Oracle WebLogic CVE-2024-21182 was also added — check for legacy WebLogic still exposed.
  • CVE-2026-28318 SolarWinds Serv-U uncontrolled resource consumption (DoS) and CVE-2026-34926 Trend Micro Apex One on-prem directory traversal both warrant priority given prior exploitation history of these products.

Web Stack, Plugins & Supply Chain

  • Two LiteSpeed cPanel Plugin issues (CVE-2026-54420 symlink following, CVE-2026-48172 privilege escalation) point to active hosting-provider targeting — shared-hosting operators should audit.
  • CVE-2026-9082 Drupal Core SQL injection and CVE-2026-48907 Widget Factory Joomla Content Editor access control round out CMS exposure. CVE-2026-45247 Mirasvit Full Page Cache Warmer deserialization affects Magento shops.
  • Supply-chain / AI-tooling additions: CVE-2026-48027 (Nx Console malicious code, ransomware-linked), CVE-2026-8398 (Daemon Tools Lite embedded malicious code), CVE-2026-42271 (BerriAI LiteLLM command injection), and CVE-2025-34291 (Langflow origin validation). The LiteLLM and Langflow entries are notable — this is CISA formally acknowledging exploitation of LLM-orchestration frameworks. Inventory any AI/agent tooling accordingly.

Endpoint, Mobile & Kernel

  • CVE-2026-11645 Chromium V8 out-of-bounds read/write — standard drive-by risk; ensure Chrome/Edge auto-update is functioning fleet-wide.
  • CVE-2025-48595 Android Framework integer overflow and CVE-2022-0492 Linux kernel improper authentication (cgroups escape, useful for container breakout) were both added end-of-May with early-June deadlines. The 2022 Linux bug re-appearing on KEV implies fresh observed exploitation, likely in container/cloud contexts.
  • CVE-2025-67038 Lantronix EDS5000 code injection targets serial-to-Ethernet device servers common in OT environments — ICS asset owners should prioritize.

Legacy Re-adds Worth Noting

CISA re-added a cluster of vintage Microsoft/Adobe bugs on 2026-05-20 (CVE-2008-4250 Windows Server Service buffer overflow — the original Conficker vector; CVE-2009-1537 DirectX; CVE-2009-3459 Adobe Reader; CVE-2010-0249 and CVE-2010-0806 IE use-after-free). These are almost certainly showing up in recent incident telemetry against unpatched legacy Windows in OT, kiosk, or embedded fleets — a reminder to sweep for XP/2003/2008-era hosts still reachable.

Analyst Takeaways

1. Immediate action: SimpleHelp (CVE-2026-48558) — 2026-07-02 deadline is tomorrow.

2. Assume-breach candidates: any environment running unpatched PeopleSoft PeopleTools, Check Point Gateway, or Nx Console given ransomware tagging and elapsed deadlines.

3. Trend to watch: first appearances of LLM-framework CVEs (LiteLLM, Langflow) on KEV — expect this category to grow through H2 2026.