
June - Top 5 vulnerabilities
Vulnerability Intelligence
The CISA Known Exploited Vulnerabilities (KEV) catalog continues its upward trajectory, with 22 new entries added in June 2026—bringing the total to 1,630 documented actively exploited flaws. This represents a 2-vulnerability increase compared to May, reflecting an accelerating threat landscape where adversaries rapidly weaponize newly disclosed exploits.

Two vulnerabilities were specifically flagged as ransomware exploitation vectors in June, underscoring the ongoing convergence between vulnerability disclosure and criminal monetization. Below, we detail the top 5 critical vulnerabilities that demand immediate patching priority based on exploitation activity and infrastructure impact.
1. Check Point Security Gateway
CVE: CVE-2026-50751 | Severity: Critical | Exploitation Status: Active by ransomware groups
Check Point Security Gateways form the backbone of enterprise network security infrastructure. A vulnerability allowing ransomware actors to circumvent firewall rules or inject malicious traffic represents one of the highest-impact scenarios possible. Once breached, attackers can deploy ransomware across the entire protected network segment while evading detection systems.
This vulnerability highlights a critical attack chain: compromise the perimeter defense → deploy ransomware → encrypt critical business data → extort payment. Organizations relying on Check Point appliances must apply patches within the 21-day federal compliance window.
2. Oracle PeopleSoft Enterprise PeopleTools
CVE: CVE-2026-35273 | Severity: Critical | Exploitation Status: Active by ransomware groups
PeopleSoft systems typically host an organization's most sensitive human resources, payroll, and financial data. When combined with ransomware exploitation, this vulnerability enables attackers to exfiltrate personally identifiable information (PII) before deploying encryption. This creates dual extortion pressure: ransom demand plus threatened public data leak.
For Swiss organizations handling employee data under GDPR constraints, this vulnerability carries significant regulatory exposure. PII breaches involving financial records or health information can trigger substantial fines alongside operational disruption.
3. Ubiquiti UniFi OS
CVE: CVE-2026-34910 | Severity: High | Exploitation Status: Three separate KEV entries in June
Ubiquiti appeared three times in June's KEV additions, signaling a concentrated attack campaign targeting UniFi environments. This platform manages wireless access points, switches, and gateways across SMB and enterprise deployments. Compromise allows attackers to:
- Intercept wireless traffic
- Modify network segmentation rules
- Credential harvesting from connected devices
- Pivot into wired network segments
The clustering of three distinct CVEs suggests either multiple unpatched components or a coordinated vulnerability disclosure. Organizations running UniFi controllers should verify all three patches are applied.
4. Cisco Catalyst SD-WAN Manager
CVE: CVE-2026-20262, CVE-2026-20245 | Severity: High | Exploitation Status: Active exploitation documented
SD-WAN controllers manage traffic routing across distributed enterprise networks. Compromise of the management plane enables attackers to redirect sensitive traffic through malicious endpoints, intercept inter-site communications, and disrupt business continuity. Two separate CVEs appearing simultaneously indicates either complementary exploit paths or different components within the same product family.
For multinational corporations with branch offices, the SD-WAN compromise represents systemic risk across the entire organizational footprint.
5. Linux Kernel
CVE: CVE-2022-0492 | Severity: Critical | Exploitation Status: Persistent long-term exploitation
Despite being originally disclosed in 2022, CVE-2022-0492 remains in the June 2026 KEV catalog—a testament to persistent exploitation across unpatched Linux environments. This container escape vulnerability enables attackers running in privileged containers to break out and gain root access on the host system.
For organizations using Kubernetes, Docker, or cloud-native infrastructure, this vulnerability bypasses isolation guarantees entirely. The continued presence in 2026 KEV lists reflects legacy system inertia: many production environments run unpatched kernel versions due to compatibility constraints or oversight.
Key Takeaways
✅ Ransomware integration continues — Two vulnerabilities specifically flagged for ransomware exploitation indicate criminal groups monitor vulnerability disclosures closely.
✅ Network infrastructure remains a priority target — Check Point, Cisco, and Ubiquiti (and obviously Fortinet before) combined represent 5 of the top 5 critical CVEs, emphasizing perimeter and SD-WAN controls as primary attack vectors.
✅ Legacy vulnerabilities persist — CVE-2022-0492 still appearing in 2026 demonstrates long-tail exploitation of unpatched systems.
References
You can also check the vendor's official security advisory or the CISA KEV catalog directly for exploitation status

