U.S. CISA adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog
2026-06-05T02:51:50Z•73362ab63a17a98ced3038ec171bb5ec46bdb26f2a10d144e294506d0de7d8dd
AndroidCISACVE-2025-48595CVE-2026-0826CVE-2026-20230CVE-2026-45247CiscoGamaredonGoogle patchHP PolyKEVMirasvitOperation KRATOSOutlook compromiseSSRFTelegram-C2VS Code zero-dayVoIPWinRARespionageknown-exploited-vulnerabilitiesmodular-malwarenear-filelesspublic-PoCroot-RCE
What happened
Multiple high/critical vulnerabilities and active threat developments were reported. CISA added the Mirasvit Full Page Cache Warmer flaw (CVE-2026-45247, CVSS 9.3) to its Known Exploited Vulnerabilities (KEV) catalog. Cisco patched a critical Unified CM flaw (CVE-2026-20230) with public PoC that enables unauthenticated SSRF. Rapid7 disclosed a critical unauthenticated stack-buffer overflow in HP Poly VoIP phones (CVE-2026-0826) leading to possible root RCE. Google’s June Android updates fix an actively exploited privilege-escalation bug (CVE-2025-48595). Separately, Gamaredon is exploiting a (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 73362ab63a17a98ced3038ec171bb5ec46bdb26f2a10d144e294506d0de7d8dd
- Enrichment time
- 2026-06-05T02:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.