CISA Adds Four Known Exploited Vulnerabilities to Catalog

2026-06-23T21:24:09Z2893d35ad7cb00fe54e46057a215557317ae74632c7f214bffb3279c9cca15b7
BOD 26-04CISACiscoFortiBleedFortinetIvantiJoomlaKEVKnown Exploited VulnerabilitiesLantronixLiteSpeedMFAOracle PeopleSoftPBKDF2SplunkUbiquiticredential exposurepatchingremediationthreat advisoryvulnerability management

What happened

CISA published multiple alerts in June 2026: it added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog (including Lantronix EDS5000 code injection, multiple Ubiquiti UniFi OS flaws, Splunk missing-auth vulnerability, Joomla plugin improper access control, Cisco SD‑WAN path traversal, LiteSpeed cPanel symlink issue, Oracle PeopleSoft missing-auth, and Ivanti OS command injection) and urged rapid remediation per Binding Operational Directive (BOD) 26‑04. Separately, CISA warned of widespread credential exposure (FortiBleed) affecting roughly 74,000 internet‑accessible

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
2893d35ad7cb00fe54e46057a215557317ae74632c7f214bffb3279c9cca15b7
Enrichment time
2026-06-23T21:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.