← Archive
Cyber Threats Daily2026-07-14July 14, 2026

KEV Floodgates Open: Ransomware-Linked Flaws Lead 40-Entry CISA Catalog Update

Ransomware Crews Already Weaponizing Four Fresh KEV Entries

CISA's latest batch flags four vulnerabilities with confirmed ransomware activity, making them the top priority regardless of remediation date. CVE-2026-35273 is a missing-authentication flaw in Oracle PeopleSoft Enterprise PeopleTools that ransomware operators are actively abusing for initial access. CVE-2026-50751 hits Check Point Security Gateway via improper authentication and has the same ransomware tag — patch or isolate exposed gateways now. Supply-chain risk is also in play: CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) both involve malicious code embedded in developer tooling, meaning compromised build pipelines rather than a single exploited endpoint.

Deadline Alert: Two Days Left on Cisco IOS CSRF

The newest addition to the catalog, CVE-2008-4128 (Cisco IOS cross-site request forgery), carries a CISA remediation deadline of 2026-07-16 — just two days out. Despite its age, federal agencies and any org running legacy Cisco IOS must confirm mitigations are in place before the window closes.

Backlog Warning: Most July Deadlines Have Already Lapsed

Nearly every other entry in this batch already has an expired federal remediation deadline (dates ranging 2026-05-20 through 2026-07-13), signaling agencies are behind on a wave of CISA-mandated patches. Notable overdue items include CVE-2026-45659 (Microsoft SharePoint Server deserialization, due 07-04), CVE-2026-48558 (SimpleHelp authentication bypass, due 07-02), and CVE-2026-0257 (Palo Alto Networks PAN-OS auth bypass, due 06-01) — all high-value targets for initial-access brokers.

CMS and Plugin Pile-Up

A cluster of arbitrary file-upload and access-control bugs hit website builders and event plugins: CVE-2026-56291 (Balbooa Forms), CVE-2026-48939 (iCagenda), CVE-2026-48908 (JoomShaper SP Page Builder), CVE-2026-56290 (Joomlack Page Builder), and CVE-2026-48907 (Widget Factory Joomla Content Editor) all allow unrestricted or improperly-controlled file uploads, a classic webshell-drop vector. CVE-2026-54420 and CVE-2026-48172, both in the LiteSpeed cPanel plugin, add symlink-following and privilege-escalation paths on the same hosting stack.

Network Edge and Infrastructure Under Fire

Cisco dominates this category: CVE-2026-20230 (Unified Communications Manager SSRF), CVE-2026-20262 (Catalyst SD-WAN Manager path traversal), and CVE-2026-20245 (SD-WAN Manager output-encoding flaw) all point to continued targeting of Cisco's collaboration and SD-WAN stacks. Ubiquiti UniFi OS drew three separate KEV entries — CVE-2026-34910, CVE-2026-34909, and CVE-2026-34908 — covering input validation, path traversal, and access control, suggesting a chained exploit chain against UniFi deployments. Round out the edge-device list with CVE-2026-7473 (Arista EOS comparison flaw), CVE-2026-28318 (SolarWinds Serv-U resource exhaustion), CVE-2026-10520 (Ivanti Sentry command injection), and CVE-2026-12569 (PTC Windchill/FlexPLM input validation).

Enterprise Platforms and Legacy OS Bugs

CVE-2026-48282 (Adobe ColdFusion path traversal), CVE-2026-20253 (Splunk Enterprise missing authentication), CVE-2026-9082 (Drupal Core SQL injection), and CVE-2026-34926 (Trend Micro Apex One on-prem directory traversal) round out server-side exposure. Older platform bugs also resurfaced: CVE-2024-21182 (Oracle WebLogic, unspecified), CVE-2022-0492 (Linux Kernel improper authentication), CVE-2025-48595 (Android Framework integer overflow), and CVE-2008-4250 (a 17-year-old Windows buffer overflow) — a reminder that KEV additions aren't limited to zero-days.

AI/Dev Tooling Exposure

Beyond the ransomware-tagged Nx Console and TanStack issues, CVE-2026-55255 (Langflow authorization bypass via user-controlled key) and its sibling CVE-2025-34291 (Langflow origin validation error) point to repeated exploitation of the AI workflow platform. CVE-2026-42271 (BerriAI LiteLLM command injection) and CVE-2026-8398 (Daemon Tools Lite embedded malicious code) close out the developer-tooling cluster — audit build environments and CI runners for these packages.