U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog

2026-06-30T20:51:42Zf79b5228b6e5a5ea5174fe129c928b8ed2bcffd7cfa4c942e541babcffb0635e
AI-assisted-discoveryAflac-JapanAppleKDDIKnown-Exploited-VulnerabilityOracle-E-Business-SuiteRussian-cyber-espionageSimpleHelpStegoAdUNC4221UNC5792WebKitcritical-vulnerabilitydata-breachmalicious-browser-extensionsmessaging-phishing

What happened

Multiple high-severity incidents and vulnerabilities reported: CISA added a critical SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. A separate critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS ~9.8) is being actively exploited to takeover Oracle Payments. Large data breaches disclosed include Aflac Japan (≈4.38M customers) and a KDDI-related incident affecting up to 14.2M email accounts. Apple released WebKit/security updates (including vulnerabilities found using AI tools). Microsoft dismantled the StegoAd campaign of 119

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f79b5228b6e5a5ea5174fe129c928b8ed2bcffd7cfa4c942e541babcffb0635e
Enrichment time
2026-06-30T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog · Baitaphish