Cyber Threats Daily — 2026-07-13
TITLE: KEV Backlog Alert: Ransomware-Linked Flaws in Oracle, Check Point Overdue as Dozens of Deadlines Lapse
---
Lead: Ransomware Crews Are Already Inside These
CISA's latest KEV batch confirms four vulnerabilities with known ransomware use, and all four remediation deadlines have already passed as of today. CVE-2026-35273, a missing-authentication flaw in Oracle PeopleSoft Enterprise PeopleTools, was due 2026-06-15 and is a textbook ransomware entry point for ERP environments. CVE-2026-50751, an improper-authentication bug in Check Point Security Gateway, missed its 2026-06-11 deadline — treat any exposed gateway as compromised until patched and hunt for post-exploit persistence. On the software-supply-chain side, CVE-2026-48027 (Nx Console embedded malicious code) and CVE-2026-45321 (TanStack, unspecified) both carried a 2026-06-10 deadline and point to compromised dev-tooling packages being weaponized for ransomware staging — audit build pipelines that pulled these packages in the affected window.
Backlog Warning: Nearly Every Deadline in This Batch Has Lapsed
Of the 40 entries in today's feed, only two — CVE-2026-56291 (Balbooa Forms unrestricted file upload) and CVE-2026-48939 (iCagenda unrestricted file upload) — have remediation due *today*, 2026-07-13. Every other item in this list carries a due date already in the past, some by nearly six weeks. This isn't a "watch list," it's an active compliance gap for federal agencies still exposed on: Adobe ColdFusion path traversal (CVE-2026-48282), Microsoft SharePoint Server deserialization (CVE-2026-45659, due 2026-07-04), and SimpleHelp authentication bypass (CVE-2026-48558, due 2026-07-02). Patch these first if they're still open in your environment.
Network Edge and Enterprise Infrastructure
Perimeter and remote-access gear dominates the overdue stack. Cisco contributed three: Unified Communications Manager SSRF (CVE-2026-20230), and two Catalyst SD-WAN Manager bugs — directory/path traversal (CVE-2026-20262) and output-encoding issues (CVE-2026-20245). Palo Alto Networks PAN-OS has an authentication bypass (CVE-2026-0257, due 2026-06-01) that's now six weeks overdue. Ubiquiti UniFi OS racked up three separate CVEs — input validation (CVE-2026-34910), path traversal (CVE-2026-34909), and access control (CVE-2026-34908) — all sharing a 2026-06-26 deadline, suggesting a coordinated exploit chain against UniFi deployments. Round out the list: SolarWinds Serv-U resource exhaustion (CVE-2026-28318), Splunk Enterprise missing authentication (CVE-2026-20253), Ivanti Sentry OS command injection (CVE-2026-10520), Arista EOS comparison flaw (CVE-2026-7473), Oracle WebLogic Server (CVE-2024-21182), PTC Windchill/FlexPLM input validation (CVE-2026-12569), Trend Micro Apex One directory traversal (CVE-2026-34926), and Lantronix EDS5000 code injection (CVE-2025-67038) — the latter notable for hitting embedded/IoT device management infrastructure.
CMS Plugin Upload Cluster
A recurring pattern of unrestricted file-upload bugs is hitting the Joomla/WordPress plugin ecosystem simultaneously: CVE-2026-56291 (Balbooa Forms), CVE-2026-48939 (iCagenda), CVE-2026-48908 (JoomShaper SP Page Builder), and CVE-2026-56290 (Joomlack Page Builder) all share upload-related access-control failures and near-identical due dates (2026-07-10/13), suggesting mass scanning against these CMS extensions is already underway. Widget Factory's Joomla Content Editor access-control flaw (CVE-2026-48907) and two LiteSpeed cPanel Plugin bugs — symlink following (CVE-2026-54420) and privilege escalation (CVE-2026-48172) — extend the same theme to hosting-panel infrastructure. Mirasvit's Full Page Cache Warmer deserialization bug (CVE-2026-45247) and a Drupal Core SQL injection (CVE-2026-9082) round out the CMS-adjacent exposure.
AI/Dev-Tooling Supply Chain
Beyond the ransomware-flagged Nx Console and TanStack entries above, Langflow shows up twice — an authorization bypass via user-controlled key (CVE-2026-55255, due 2026-07-10) and an origin validation error (CVE-2025-34291) — indicating this AI workflow platform has had repeated auth-layer failures. BerriAI's LiteLLM also picked up a command injection bug (CVE-2026-42271), and Daemon Tools Lite was flagged for embedded malicious code (CVE-2026-8398), both consistent with a broader trend of dev/AI tooling becoming a preferred initial-access vector.
Legacy CVEs Resurface
Four notably old CVEs joined KEV this cycle, indicating fresh exploitation of long-patched systems still running in the wild: Linux Kernel improper authentication (CVE-2022-0492), Android Framework integer overflow (CVE-2025-48595), and two genuinely ancient Windows bugs — CVE-2008-4250 (buffer overflow) and CVE-2009-1537 (DirectX NULL byte overwrite). Their reappearance in active-exploitation feeds strongly suggests unpatched legacy Windows builds are still being targeted at scale; audit for EOL systems that may have been deprioritized.
Also Noted
Google Chromium's V8 out-of-bounds read/write (CVE-2026-11645) rounds out the browser-side risk — patch or force-update Chromium-based browsers given V8 bugs are reliably weaponized for drive-by exploitation.
