← All briefings

Cisco Unified Communications Manager · Ubiquiti UniFi OS · Lantronix EDS5000 serial-to-Ethernet device server

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-24 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

CISA added four actively exploited vulnerabilities to the KEV catalog on 2026-06-23, including three Ubiquiti UniFi OS flaws and a Lantronix EDS5000 code injection, all with a 2026-06-26 remediation deadline. A newly confirmed exploitation of CVE-2026-20230 in Cisco Unified Communications Manager is the most urgent enterprise-grade development. The FortiBleed credential-harvesting campaign has expanded scope, now confirmed to have targeted over 430,000 FortiGate firewalls globally. A malicious AI agent skill reached approximately 26,000 agents via a popular marketplace, highlighting emerging AI supply chain risk.

CRITICAL VULNERABILITIES

NEW

CVE-2026-20230 (Cisco Unified Communications Manager / Unified CM SME)

  • Affected products: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), all supported releases prior to patched versions
  • Severity: High (CVSS score not confirmed in available data)
  • EPSS: Not yet available
  • Technical detail: A server-side request forgery (SSRF) vulnerability in the web-based management interface allows an unauthenticated remote attacker to send crafted HTTP requests that cause the server to make arbitrary connections to internal or external systems. In enterprise deployments, Unified CM is typically network-accessible and integrated with internal telephony, directory, and authentication infrastructure, making SSRF exploitation a viable pivot point for internal reconnaissance and lateral movement. No authentication is required.
  • Exploitation status: Actively exploited in the wild, confirmed by BleepingComputer on 2026-06-23.
  • Remediation: Apply Cisco security patches immediately. Restrict management interface access to trusted administrative networks. Monitor for anomalous outbound HTTP connections originating from Unified CM servers.

CVE-2026-34910 / CVE-2026-34909 / CVE-2026-34908 (Ubiquiti UniFi OS)

  • Affected products: Ubiquiti UniFi OS (all affected versions; specific version ranges not published in available data)
  • Severity: Not individually scored in available data; CISA KEV listed
  • EPSS: Not available
  • Technical detail: Three distinct flaws affect UniFi OS, the operating system underpinning Ubiquiti’s widely deployed network infrastructure including UniFi Dream Machines, Cloud Gateways, and Network Video Recorders. CVE-2026-34910 is an improper input validation flaw enabling command injection by a network-adjacent attacker. CVE-2026-34909 is a path traversal vulnerability allowing file access on the underlying system, potentially enabling account compromise. CVE-2026-34908 is an improper access control flaw permitting unauthorized system configuration changes. All three require network access but not authentication, making them exploitable by any attacker with LAN or management-network access. UniFi devices are prevalent in European SMB and enterprise branch environments.
  • Exploitation status: All three actively exploited; added to CISA KEV on 2026-06-23 with deadline 2026-06-26.
  • Remediation: Apply UniFi OS firmware updates immediately. Isolate UniFi management interfaces from untrusted networks. Audit device configurations for unauthorized changes. CISA deadline is 2026-06-26 for federal agencies; treat as urgent for all organizations.

CVE-2025-67038 (Lantronix EDS5000)

  • Affected products: Lantronix EDS5000 serial-to-Ethernet device server
  • Severity: Not individually scored; CISA KEV listed (CWE-78 OS command injection, CWE-94 code injection)
  • EPSS: Not available
  • Technical detail: A code injection vulnerability in the username parameter of the EDS5000 web interface allows an unauthenticated attacker to inject arbitrary OS commands that execute with root privileges. The EDS5000 is a serial device server used to connect legacy serial equipment to IP networks, commonly deployed in industrial, healthcare, and building management environments. While primarily an OT-adjacent device, its network-facing web interface and root-level execution make it a viable pivot point in enterprise network segments where such devices are present.
  • Exploitation status: Actively exploited; added to CISA KEV on 2026-06-23 with deadline 2026-06-26.
  • Remediation: Apply Lantronix firmware updates. If patching is not immediately possible, restrict web interface access via firewall rules and place devices on isolated management VLANs. Audit for unauthorized configuration changes.

CVE-2026-11807 (Red Hat Ansible Automation Platform — Event-Driven Ansible)

  • Affected products: Red Hat Ansible Automation Platform 2.5 and 2.6 (Event-Driven Ansible component)
  • Severity: CVSS 9.6
  • EPSS: 0 (newly published; no exploitation data yet)
  • Technical detail: A missing authorization check in the Event-Driven Ansible (EDA) websocket API endpoint /api/eda/ws/ansible-rulebook allows an unauthenticated attacker to send Worker messages without any permission verification. EDA is used to trigger automated remediation and operational workflows in response to events; unauthorized message injection could cause arbitrary automation jobs to execute, potentially affecting managed infrastructure at scale. Red Hat Ansible Automation Platform is widely deployed in European enterprise and public sector environments for infrastructure automation.
  • Exploitation status: No confirmed in-the-wild exploitation. CVSS 9.6 and unauthenticated attack vector make this a high-priority patch.
  • Remediation: Apply Red Hat patches (patch IDs 1781732675 for AAP 2.6, 1781741251 for AAP 2.5) via the Red Hat Customer Portal. Restrict EDA websocket endpoint access to trusted networks pending patching.

CVE-2026-41862 (Spring Statemachine)

  • Affected products: Spring Statemachine 3.2.0 through 3.2.4, 4.0.0 through 4.0.1.0
  • Severity: CVSS 8.8
  • EPSS: 0 (newly published)
  • Technical detail: Kryo-based persistence backends in Spring Statemachine (JPA, MongoDB, Redis, and ZooKeeper) deserialize persisted state-machine contexts without enforcing a class allowlist, constituting an unsafe deserialization vulnerability (CWE-502). An attacker with write access to the persistence backend — achievable via a compromised database, cache, or coordination service — can craft a malicious serialized payload that executes arbitrary code upon deserialization. Spring Statemachine is used in enterprise Java applications for workflow and process orchestration.
  • Exploitation status: No confirmed in-the-wild exploitation.
  • Remediation: Upgrade to Spring Statemachine 3.2.5 or 4.0.1.1. Restrict write access to persistence backends (Redis, MongoDB, ZooKeeper, JPA data stores) to trusted application principals only.

ONGOING

  • CVE-2026-10561 / CVE-2026-7664 (IBM Langflow OSS): unauthenticated RCE; upgrade to 1.9.4+ and 1.8.5+; isolate internet-exposed instances.
  • CVE-2026-56422 / CVE-2026-56447 / CVE-2026-56446 (MISP): privilege escalation and file read; upgrade to 2.5.42+.
  • CVE-2026-20262 (Cisco Catalyst SD-WAN Manager): actively exploited; CISA KEV deadline 2026-06-29; patch immediately.
  • CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect): actively exploited; apply PAN-OS patches.
  • CVE-2026-5027 (Langflow): actively exploited; isolate from internet.
  • CVE-2026-50751 (Check Point Security Gateway): actively exploited; apply hotfix sk185033.
  • CVE-2026-4020 (Gravity SMTP WordPress): actively exploited; update plugin and rotate credentials.
  • CVE-2026-42271 (LiteLLM): CISA KEV deadline passed; verify patch completion.

EUROPEAN ADVISORIES

BSI published one new advisory and multiple updates on 2026-06-23.

WID-SEC-2026-2038 (Angular — NEW): BSI rates this high severity. Multiple vulnerabilities in Angular allow remote attackers to execute arbitrary code, conduct cross-site scripting attacks, disclose information, bypass security controls, and cause denial of service. Organizations running Angular-based web applications should apply the latest Angular security releases and review application-level input handling.

BSI published updates to a large number of existing advisories on 2026-06-23, covering Linux Kernel (multiple advisories: WID-SEC-2026-0086, 0324, 0421, 0614, 0774, 1232, 1279, 1430, 1870, and WID-SEC-2025-1465, 2077, 2099), MariaDB (WID-SEC-2026-0815), OpenSSL (WID-SEC-2026-0234), Golang Go (WID-SEC-2026-0548), PostgreSQL (WID-SEC-2026-1544), strongSwan (WID-SEC-2025-2846), ISC BIND (WID-SEC-2025-2392), Kiali for Red Hat OpenShift Service Mesh (WID-SEC-2026-1513), Red Hat Enterprise Linux components (corosync, freeipmi, JWCrypto, python-markdown), Red Hat OpenShift Container Platform (gRPC-Go), and WebKitGTK (WID-SEC-2026-1766). These are maintenance updates to previously reported advisories; apply outstanding patches per vendor guidance.

CISA published ICS advisories for Siemens products (OpenSSL-based products, WinCC Certificate Manager, SIPROTEC 5, SINEC INS), Hubbell Aclara Metrum, ABB Freelance Security Lock, and B&R Linux Kernel impact. These are primarily OT/ICS-scoped; the Siemens OpenSSL advisory is relevant to enterprise environments running affected Siemens software components — apply available Siemens product updates.

ACTIVE THREATS AND CAMPAIGNS

STATUS CHANGE — FortiBleed Campaign New reporting from The Hacker News on 2026-06-23 confirms the campaign has targeted over 430,000 FortiGate firewalls globally and has been active since February 2026. The threat actor is assessed as a Russian-speaking initial access broker (IAB) motivated by financial gain, conducting credential list collection, exposed service enumeration, brute-forcing, and custom sniffer deployment. The scale materially exceeds prior estimates. All organizations with internet-exposed FortiGate devices should assume credential exposure and rotate secrets accordingly.

NEW — AI Supply Chain: Malicious Skills in Agent Marketplaces Unit 42 and independent researcher AIR have separately documented malicious AI agent skills distributed via popular skill marketplaces that bypass automated security scanners. Unit 42’s OpenClaw/ClawHub analysis identified evasive skills deploying infostealers and enabling agentic financial fraud. AIR demonstrated a proof-of-concept skill that reached approximately 26,000 agents including corporate accounts. Organizations deploying AI agent platforms should establish a vetting process for third-party skills and restrict agent marketplace access to approved sources.

NEW — macOS ClickFix Infostealer Campaign A new macOS ClickFix variant uses Terminal commands to silently download, mount, and execute infostealer malware from malicious DMG files. Apple has introduced terminal prompt protections in recent macOS versions to intercept suspicious commands. Ensure macOS endpoints are updated and monitor for unexpected Terminal activity or DMG mounts.

NEW — Malicious npm Packages Impersonating PostCSS Tools Three malicious npm packages (postcss-minify-selector, postcss-minify-selector-parser, aes-decode-runner-pro) were identified delivering a Windows-based remote access trojan. Combined download count exceeds 1,000. Development teams should audit npm dependencies and remove affected packages immediately.

ONGOING — WhatsApp VBScript campaign: fake business documents delivering RMM tool payloads; block VBScript execution and brief users. ONGOING — ShapedPlugin WordPress supply chain: audit Pro plugin installations for backdoors and unauthorized admin accounts. ONGOING — Gentlemen RaaS / GentleKiller: EDR killer in active distribution; verify tamper protection on all endpoints.

SECURITY NEWS AND CONTEXT

LastPass confirmed a data breach affecting its Salesforce environment following theft of OAuth tokens in the Klue supply chain attack earlier in June. Organizations using LastPass enterprise should review shared credential exposure and consider rotating master credentials.

Two Scattered Spider members pleaded guilty to the 2024 hack of Transport for London, confirming the group’s continued legal exposure. The TfL incident remains a reference case for social engineering and SIM-swapping against critical infrastructure operators.

A US executive order signed 2026-06-22 mandates federal agencies migrate high-value assets to post-quantum cryptography by 2026-12-31 and digital signatures by 2027-12-31. European organizations should use this as a benchmark for their own PQC migration planning.

GitHub updated actions/checkout (effective 2026-06-18) to block pwn request attack patterns exploiting pull_request_target workflow triggers. Organizations using GitHub Actions should verify they are on the latest version of actions/checkout.

RECOMMENDED ACTIONS

  1. Patch Cisco Unified CM and Unified CM SME immediately for CVE-2026-20230 (SSRF, actively exploited); restrict management interface to trusted networks.
  2. Update Ubiquiti UniFi OS firmware for CVE-2026-34908/34909/34910 before the CISA KEV deadline of 2026-06-26; audit device configurations for unauthorized changes.
  3. Apply Lantronix EDS5000 firmware update for CVE-2025-67038 before 2026-06-26; restrict web interface access via firewall if patching is delayed.
  4. Apply Red Hat patches for CVE-2026-11807 (EDA websocket missing authorization, CVSS 9.6) on Ansible Automation Platform 2.5 and 2.6; restrict EDA endpoint network access.
  5. Upgrade Spring Statemachine to 3.2.5 or 4.0.1.1 (CVE-2026-41862); restrict write access to Kryo persistence backends.
  6. Apply BSI WID-SEC-2026-2038 Angular security updates; review Angular application input handling.
  7. Rotate all credentials on FortiGate-connected systems given FortiBleed’s confirmed scale of 430,000+ devices; enforce MFA on all accounts.
  8. Audit AI agent platform skill sources; restrict third-party skill installation to vetted and approved sources only.
  9. Audit npm dependencies for malicious PostCSS impersonators; remove postcss-minify-selector, postcss-minify-selector-parser, and aes-decode-runner-pro.
  10. Continue remediation of previously reported items: CVE-2026-20262 (Cisco SD-WAN, KEV deadline 2026-06-29), CVE-2026-42271 (LiteLLM, KEV deadline passed), CVE-2026-10561/7664 (IBM Langflow), CVE-2026-56422 (MISP), CVE-2026-0257 (PAN-OS), CVE-2026-5027 (Langflow), CVE-2026-50751 (Check Point), CVE-2026-4020 (Gravity SMTP).