U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog
2026-06-30T20:51:42Z•f79b5228b6e5a5ea5174fe129c928b8ed2bcffd7cfa4c942e541babcffb0635e
AI-assisted-discoveryAflac-JapanAppleKDDIKnown-Exploited-VulnerabilityOracle-E-Business-SuiteRussian-cyber-espionageSimpleHelpStegoAdUNC4221UNC5792WebKitcritical-vulnerabilitydata-breachmalicious-browser-extensionsmessaging-phishing
What happened
Multiple high-severity incidents and vulnerabilities reported: CISA added a critical SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. A separate critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS ~9.8) is being actively exploited to takeover Oracle Payments. Large data breaches disclosed include Aflac Japan (≈4.38M customers) and a KDDI-related incident affecting up to 14.2M email accounts. Apple released WebKit/security updates (including vulnerabilities found using AI tools). Microsoft dismantled the StegoAd campaign of 119
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f79b5228b6e5a5ea5174fe129c928b8ed2bcffd7cfa4c942e541babcffb0635e
- Enrichment time
- 2026-06-30T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.