← Archive
Cyber Threats Daily2026-06-06June 6, 2026

Cyber Threats Daily — 2026-06-06

TITLE: Cyber Threats Daily — KEV surge: SolarWinds Serv-U, PAN-OS auth bypass, ransomware abusing SimpleHelp & cPanel

---

Top of the queue: Fresh KEV additions with imminent deadlines

CISA's KEV catalog saw heavy churn over the past two weeks. The freshest additions carrying near-term federal remediation deadlines:

  • CVE-2026-28318 — SolarWinds Serv-U uncontrolled resource consumption was added 2026-06-05 with a remediation deadline of 2026-06-19. File-transfer servers remain a favorite ransomware foothold; prioritize patching internet-exposed Serv-U instances this week.
  • CVE-2026-45247 — Mirasvit Full Page Cache Warmer deserialization of untrusted data was added 2026-06-03 with a 2026-06-06 due date (today). Magento/Adobe Commerce shops running this extension should treat this as overdue and hunt for webshells.
  • CVE-2026-0257 — A Palo Alto Networks PAN-OS authentication bypass landed in KEV on 2026-05-29; the federal deadline (2026-06-01) has already lapsed. Any unpatched management plane reachable from untrusted networks should be assumed compromised pending IR triage.
  • CVE-2024-21182 — Oracle WebLogic Server unspecified vulnerability was added 2026-06-01 with deadline 2026-06-04 (now past). Legacy WebLogic continues to be hit by cryptominers and initial-access brokers.

Ransomware-flagged entries — assume active campaigns

CISA explicitly tagged several recent KEV adds as known ransomware vectors. Treat these as IR-grade priorities:

  • CVE-2024-57728 and CVE-2024-57726 — Twin SimpleHelp flaws (path traversal + missing authorization) are being chained by ransomware crews against MSP-hosted instances; KEV deadline was 2026-05-08. If you outsource remote support, demand attestation from your provider.
  • CVE-2026-41940 — Missing authentication for critical function in WebPros cPanel & WHM / WP2 (deadline 2026-05-03) is under active ransomware abuse, exposing shared-hosting fleets to mass takeover.
  • CVE-2024-1708 — ConnectWise ScreenConnect path traversal remains in active ransomware rotation more than two years after disclosure; deadline 2026-05-12. Audit on-prem ScreenConnect deployments against current builds.
  • CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) — Both are embedded-malicious-code / supply-chain entries with ransomware ties and a 2026-06-10 deadline. Developer toolchains are now KEV territory; review CI/CD package pinning and lockfiles.
  • CVE-2023-27351 — PaperCut NG/MF improper authentication is back on the deadline radar (2026-05-04) as ransomware operators revisit print-management servers for lateral movement.

Network edge and management planes under pressure

  • CVE-2026-20182 — Cisco Catalyst SD-WAN Controller authentication bypass (KEV deadline 2026-05-17) joins CVE-2026-20122 and CVE-2026-20133 in SD-WAN Manager, indicating a sustained campaign against Cisco SD-WAN fabrics. Rotate credentials and review controller logs for unauthorized policy pushes.
  • CVE-2026-0300 — A PAN-OS out-of-bounds write (deadline 2026-05-09) compounds the earlier auth-bypass story; assume chained exploitation is plausible against unpatched firewalls.
  • CVE-2026-6973 — Ivanti EPMM improper input validation (deadline 2026-05-10) continues the long-running Ivanti exploitation arc; MDM compromise yields device-level reach into managed fleets.
  • CVE-2025-29635 — D-Link DIR-823X command injection (deadline 2026-05-08) extends botnet recruitment of SOHO routers; ISP and edge defenders should sinkhole known C2.

Microsoft footprint: Defender, Exchange, and a wave of legacy re-adds

  • CVE-2026-41091 (Defender link-following), CVE-2026-45498 (Defender DoS), and CVE-2026-33825 (Defender access-control granularity) signal attackers explicitly targeting the EDR itself. Verify tamper-protection telemetry is intact and centrally logged.
  • CVE-2026-42897 — Microsoft Exchange Server XSS (deadline 2026-05-29) is exploitable for session theft against admins; pair patching with OWA session review.
  • CVE-2026-32202 — Windows protection-mechanism failure (deadline 2026-05-12) appears alongside an unusual cluster of pre-2011 re-additions — CVE-2008-4250 (Windows buffer overflow / Conficker-era), CVE-2009-1537 (DirectX), CVE-2009-3459 (Acrobat/Reader), CVE-2010-0249 and CVE-2010-0806 (Internet Explorer UAFs). The re-listing strongly implies fresh in-the-wild abuse against under-managed legacy systems in critical-infrastructure environments; if you still operate XP/Win7-era endpoints, segment now.

Web apps, AI infra, and developer tools

  • CVE-2026-9082 — Drupal core SQL injection (deadline 2026-05-27) warrants immediate emergency patching across public CMS estates.
  • CVE-2025-2749 — Kentico Xperience path traversal (deadline 2026-05-04) and CVE-2025-48700 — Zimbra Collaboration Suite XSS (deadline 2026-04-23) remain in active exploitation against enterprise web stacks.
  • CVE-2026-34926 — Trend Micro Apex One (On-Premise) directory traversal (deadline 2026-06-04) is notable because the security tool itself is the entry point.
  • CVE-2025-34291 (Langflow origin validation), CVE-2026-42208 (BerriAI LiteLLM SQL injection), and CVE-2026-39987 (Marimo RCE) confirm what red teams have been signaling: AI/LLM orchestration platforms are being weaponized as soft underbellies in enterprise networks. Inventory shadow-AI deployments and put them behind auth proxies.
  • CVE-2026-48172 — LiteSpeed cPanel Plugin privilege escalation (deadline 2026-05-29) and CVE-2026-8398 — Daemon Tools Lite embedded malicious code (deadline 2026-05-30) round out the supply-chain themed adds.

Kernel and mobile

  • CVE-2022-0492 — Linux kernel improper authentication (cgroups release_agent) returned to KEV with a 2026-06-05 deadline, indicating renewed container-escape activity. Audit Kubernetes node patch levels and seccomp profiles.
  • CVE-2026-31431 — A second Linux kernel entry (incorrect resource transfer between spheres, deadline 2026-05-15) suggests ongoing container/namespace boundary exploitation.
  • CVE-2025-48595 — Android Framework integer overflow (deadline 2026-06-05) and CVE-2024-7399 — Samsung MagicINFO 9 Server path traversal (deadline 2026-05-08) extend exposure to mobile and digital-signage fleets often outside standard patch windows.

Analyst takeaway

This cycle's KEV activity is dominated by three themes: ransomware operators consolidating around remote-support and hosting-control tooling (SimpleHelp, ScreenConnect, cPanel, PaperCut); sustained pressure on network-edge management planes (PAN-OS, Cisco SD-WAN, Ivanti EPMM); and the unusual re-listing of decade-old Microsoft client vulnerabilities, which strongly suggests targeted campaigns against unsupported endpoints in OT/ICS-adjacent environments. Patch ordering should reflect that, not raw CVSS.