CISA added two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox to KEV on July 16, 2026. BOD 26-04 gave FCEB agencies until July 19 to patch. Both are CVSS 9.1.
Microsoft's DART discovered CVE-2026-56155 during a live intrusion. CISA added it to KEV on July 14. Patch KB 5121391 audits DKM ACLs today, auto-remediates October 13.
CISA added SonicWall SMA1000 zero-days CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 to KEV on July 14, chained by Rapid7 MDR. Federal deadline July 17.
CISA added SharePoint auth-bypass CVE-2026-56164 to KEV on July 14 and re-issued a hardening alert citing three chained on-prem SharePoint CVEs under active exploitation. FCEB deadline July 17.
SonicWall confirms in-the-wild chaining of an unauth SSRF (CVE-2026-15409, CVSS 10.0) and a post-auth command injection (CVE-2026-15410, CVSS 7.2) on SMA1000 6210/7210/8200v. CISA KEV due 2026-07-17.
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Page Builder CK) to KEV on July 7. Both CVSS 10.0, unauth file-upload to RCE. FCEB deadline: July 10.
CISA added the Langflow /api/v1/responses IDOR (CVE-2026-55255, CVSS 9.9) to KEV on July 7. Sysdig first observed exploitation on June 25. Third Langflow flaw to hit KEV in seven months.
CISA added SharePoint RCE CVE-2026-45659 to the KEV catalog on July 1 after confirmed exploitation. Deserialization bug patched OOB May 21; FCEB agencies have three days.
CISA added the SimpleHelp OIDC auth bypass (CVSS 10) to KEV on June 29. ~14,000 servers are internet-exposed; 5.5.16 and 6.0 RC2 shipped the fix on June 9.
CISA gave federal agencies three days to patch the Bulletin 064 UniFi OS triple — access control bypass, path traversal, command injection — all CVSS 10.0, all exploited.
CISA added the CVSS 9.8 command-injection bug — plus three perfect-10 UniFi OS flaws — to KEV on June 23. BOD 26-04 forces federal patching by June 26.
CISA added the CVSS 10 deserialization RCE in Windchill PDMLink and FlexPLM to KEV on June 25. PTC ships patches, BSI repeats the alarm. Three days to act.
CVE-2026-20253 is a CVSS 9.8 missing-authentication flaw in Splunk Enterprise 10. CISA added it to KEV on June 18 with a three-day patch deadline. WatchTowr published a working RCE exploit.
Second Cisco Catalyst SD-WAN Manager zero-day in two weeks. CVE-2026-20262 is an arbitrary file write under exploitation; CISA gave agencies until June 29 to patch.
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.
Google's June 8 Stable Channel pushes 149.0.7827.102/.103 for an actively exploited V8 out-of-bounds read/write. CISA added the CVE to KEV the next day.
VulnCheck added CVE-2026-5027 to its KEV on June 8 after detecting in-the-wild exploitation. Path traversal in /api/v2/files yields unauth RCE; ~7,000 instances are publicly exposed.
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
CISA added the two-year-old Oracle WebLogic auth-bypass CVE-2024-21182 to KEV on June 1, citing active exploitation. Federal agencies have until June 4 to patch.
Google's June 2026 Android Security Bulletin fixes 124 flaws, including a Framework integer overflow under limited, targeted exploitation. CISA wants federal agencies patched by 5 June.
PAN-OS portals with authentication-override cookies on a shared certificate let attackers forge a valid session. Rapid7 observed exploitation since May 17. Federal patch deadline June 19.
CISA added CVE-2025-34291 to the KEV catalog on May 21. An overly permissive CORS plus a misconfigured refresh-token cookie chain to account takeover and code execution in Langflow ≤ 1.6.9.