Exploited Ubiquiti UniFi OS and Lantronix Flaws Hit CISA KEV; Cisco CUCM and SD-WAN Bugs Under Active Attack

This brief covers the trailing ~48 hours (June 24–26, 2026). Every item below was verified against its primary source — CISA KEV alerts, vendor advisories, and original vendor research — with disclosure or exploitation activity confirmed inside the window.

Ubiquiti UniFi OS unauthenticated RCE chain exploited as zero-days, added to CISA KEV

CISA / Ubiquiti · June 23, 2026

CISA added three maximum-severity Ubiquiti UniFi OS flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-34908 (improper access control, CVSS 10.0), CVE-2026-34909 (path traversal), and CVE-2026-34910 (improper input validation/command injection, CVSS 10.0). Chained together, they give a remote, unauthenticated, network-adjacent attacker code execution on UniFi OS devices. Ubiquiti shipped fixes in UniFi OS Server 5.0.8 on May 21 without acknowledging in-the-wild abuse, but users reported attacks that created rogue administrator accounts under the username “John Sim,” and BishopFox published an analysis of the unauthenticated RCE chain. CISA ordered federal agencies to patch by June 26 under BOD 26-04.

“We confirmed the bypass against a live [UniFi OS version] 5.0.6 virtual machine. Requests built this way reached internal backends that are supposed to require authentication.” — BishopFox

Source: CISA KEV alert; Ubiquiti Security Advisory Bulletin 064; BishopFox analysis; SecurityWeek

Lantronix EDS5000 command injection added to CISA KEV alongside the Ubiquiti flaws

CISA / Lantronix · June 23, 2026

CISA added CVE-2025-67038 (CVSS 9.8), an unauthenticated OS command-injection flaw in the Lantronix EDS5000 serial-to-IP converter, to the KEV catalog in the same update. The HTTP RPC module fails to sanitize the username parameter before concatenating it into a shell command used to log failed authentication attempts, allowing arbitrary OS commands to run with root privileges. The bug was originally disclosed in April as part of the BRIDGE:BREAK set of Lantronix and Silex vulnerabilities affecting OT and healthcare environments; it now carries the same June 26 federal patch deadline.

Source: CISA KEV alert; CVE.org record; SecurityWeek

Cisco Unified CM WebDialer SSRF (CVE-2026-20230) seen exploited in the wild

Cisco / Defused Cyber · June 24, 2026

Researchers reported active exploitation of CVE-2026-20230 (CVSS 8.6), an unauthenticated server-side request forgery flaw in Cisco Unified Communications Manager that can be used to write files and ultimately escalate to root. Cisco previously rated the issue Critical and confirmed public proof-of-concept code; exploitation is only possible where the WebDialer service is enabled, which is off by default. Cisco PSIRT had not confirmed in-the-wild abuse, and the flaw was not yet listed in CISA KEV at the time of reporting. Cisco recommends disabling WebDialer until patches (14SU6, 15SU5/COP1) are applied.

“Over the weekend we observed exploitation of CVE-2026-20230 – Cisco Unified CM (CUCM) WebDialer SSRF → root file-write (CVSS 8.6)… This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys.” — Defused (@DefusedCyber)

Source: Cisco advisory; Security Affairs

Mandiant: Cisco Catalyst SD-WAN zero-day (CVE-2026-20245) exploited months before disclosure

Google Mandiant / Cisco · June 25, 2026

Mandiant disclosed that an unknown threat actor exploited CVE-2026-20245 (CVSS 7.8) in Cisco Catalyst SD-WAN Manager as a zero-day at least two months before it was publicly disclosed. The flaw lets an authenticated attacker with netadmin privileges run arbitrary commands as root via a crafted file upload; attackers chained it with earlier authentication-bypass bugs (CVE-2026-20127, CVE-2026-20182) to reach netadmin in the first place. Mandiant observed intrusions against a communications service provider between late 2025 and March 2026, including creation of a rogue “troot” root account and extensive anti-forensic cleanup. Cisco has confirmed active exploitation and released fixes.

“In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.” — Mandiant

Source: Mandiant report; Cisco advisory; Security Affairs


This brief covers the trailing ~48 hours (June 24–26, 2026).

Primary sources:

OpenAI and Broadcom Unveil the ‘Jalapeño’ Inference Chip, Anthropic Launches Claude Tag for Slack, and New Data on Codex Taking Over Knowledge Work

This brief covers the trailing ~72 hours (June 23–26, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. It was a busy stretch led by OpenAI — a custom inference chip, a new economic-research paper, and a science case study — alongside Anthropic shipping a new way to work with Claude.

OpenAI and Broadcom unveil “Jalapeño,” a custom LLM inference chip

OpenAI · June 24, 2026

OpenAI and Broadcom unveiled Jalapeño, OpenAI’s first Intelligence Processor: an accelerator designed from scratch for LLM inference and the first chip in a multi-generation compute platform the two companies are building together. OpenAI says the program went from initial design to manufacturing tape-out in nine months — what it believes is the fastest ASIC development cycle ever for a high-performance advanced semiconductor — with parts of the design accelerated by OpenAI’s own models. Engineering samples are already running ML workloads in the lab, and the platform is targeted for initial deployment at gigawatt scale by the end of 2026.

“Jalapeño is part of our long-term full-stack infrastructure strategy to make compute more abundant, resulting in AI which is faster, more reliable, more affordable for people and businesses, and can be used to solve more important problems.” — Greg Brockman, President and Co-Founder, OpenAI

Source: OpenAI and Broadcom unveil LLM-optimized inference chip

Anthropic introduces Claude Tag, starting on Slack

Anthropic · June 23, 2026

Anthropic launched Claude Tag, a way for teams to delegate work to Claude as a member of a Slack channel. Anyone in a channel can tag @Claude to hand off a task, and the model builds context over time, takes initiative when “ambient” behavior is enabled, and can work asynchronously over hours or days with tightly scoped, admin-controlled access to tools and data. It runs on Opus 4.8, is available today in beta for Claude Enterprise and Team customers, and replaces the existing Claude in Slack app.

“Tagging @Claude is now one of the main ways we get things done at Anthropic. Today, 65% of our product team’s code is created by our internal version of Claude Tag.” — Anthropic

Source: Introducing Claude Tag

OpenAI publishes economic-research paper on Codex adoption

OpenAI · June 25, 2026

OpenAI released an Economic Research paper, “The shift to agentic AI: evidence from Codex,” documenting how agentic tools are changing knowledge work. The company reports that by May 2026, 80.6% of sampled individual Codex users made at least one request estimated to exceed 30 minutes of human work and 25.6% made one estimated to exceed eight hours. Internally, Codex has become the primary AI tool for every department — including Legal, Finance, and Recruiting — and non-developer adoption grew 137x among individual users since August 2025.

“As the tools improve, people use them for longer, more complex, and more cross-functional work. As time goes on, this is likely to be what the future of work looks like.” — OpenAI

Source: How agents are transforming work

OpenAI details how GPT-5 helped solve a 3-year-old immunology mystery

OpenAI · June 23, 2026

OpenAI published a case study on immunologist Derya Unutmaz of The Jackson Laboratory, who used GPT-5 Pro to revisit a shelved 2022 experiment on how glucose shapes T-cell development. The model proposed a mechanism — that deoxyglucose interferes with the protein IL-2, removing a barrier to T cells becoming inflammatory Th17 cells — and, in a separate test, correctly predicted the result of an unpublished experiment on lymphoma-killing CD8+ cells. OpenAI notes that subject-matter expertise remains essential to judge the significance of any AI-generated insight.

“GPT-5 came up with this really remarkable insight that retrospectively, makes perfect sense.” — Dr. Derya Unutmaz, The Jackson Laboratory and the University of Connecticut

Source: How GPT-5 helped immunologist Derya Unutmaz solve a 3-year-old mystery


This brief covers the trailing ~72 hours (June 23–26, 2026).

Primary sources:

Cisco Unified CM SSRF-to-Root Exploited, LastPass Caught in Klue Salesforce Breach, and Critical NGINX RCE Flaws

This brief covers the trailing ~48 hours (June 22–24, 2026). Every item below was checked against its primary advisory, vendor statement, or original research before inclusion; CVE IDs are traced to their canonical source. A quiet patch window means the verified, in-window list is short, followed by several active campaigns that are still developing.

Cisco Unified CM WebDialer SSRF (CVE-2026-20230) now exploited in the wild

Cisco / Defused · June 23, 2026

Threat intelligence firm Defused reported active exploitation of CVE-2026-20230, an unauthenticated server-side request forgery flaw in the WebDialer service of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. The bug carries a CVSS base score of 8.6 but Cisco assigns it a Security Impact Rating of Critical because successful exploitation can write arbitrary files and escalate to root. Cisco shipped fixes on June 3; proof-of-concept code from SSD Secure is now public, and the observed activity to date appears to be reconnaissance-style scanning from a single IP. It is not yet listed in CISA KEV.

“Over the weekend we observed exploitation of CVE-2026-20230 — Cisco Unified CM (CUCM) WebDialer SSRF → root file-write (CVSS 8.6). No previously recorded exploitation, and not yet listed in CISA KEV.” — Defused

Source: Cisco advisory (cisco-sa-cucm-ssrf-cXPnHcW) · SSD Secure write-up · BleepingComputer

LastPass confirms data theft in Klue / “Icarus” Salesforce supply-chain breach

LastPass / Klue · June 23, 2026

LastPass confirmed that customer support-case and CRM records were stolen from its Salesforce environment through the breach at market-intelligence vendor Klue, whose integration infrastructure was compromised on June 12 via a legacy credential, allowing attackers to abuse OAuth tokens connecting Klue to customers’ Salesforce instances. The extortion group “Icarus” has publicly claimed the campaign, and the disclosed victim roster has grown to include Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. LastPass says its password vaults, product infrastructure, and payment data were not affected; exposed data was limited to Salesforce CRM records such as names, contact details, and support cases.

“On June 12, we identified unauthorized activity affecting a portion of Klue’s integration infrastructure… The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments.” — Jason Smith, CEO, Klue

Source: Klue security incident update · TechCrunch · BleepingComputer

Still developing

F5 ships out-of-band patches for critical NGINX RCE flaws (CVE-2026-42530, CVE-2026-42055)

F5 · June 17, 2026 (updated June 22)

F5 issued out-of-band fixes for two critical NGINX Open Source vulnerabilities, each rated CVSS v4 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QUIC module (ngx_http_v3_module); CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy/gRPC path (ngx_http_proxy_v2_module and ngx_http_grpc_module). Both are remotely triggerable by unauthenticated attackers on non-default configurations and can lead to denial of service or code execution. Fixes are in NGINX Open Source 1.31.2, NGINX Plus 37.0.2.1, and NGINX Gateway Fabric 2.6.4. No confirmed in-the-wild exploitation has been reported.

Source: F5 advisory (K000161616) · The Hacker News · BleepingComputer

“FortiBleed” leak exposes credentials for ~73,000 Fortinet FortiGate devices

Security researcher Bob Diachenko · June 17, 2026

Researcher Bob Diachenko disclosed an exposed dataset, dubbed FortiBleed, containing valid VPN credentials and configuration data for roughly 73,932 internet-facing FortiGate firewalls across 194 countries — estimated at about half of all internet-reachable FortiGate devices. The underlying weakness stems from FortiOS storing administrator passwords as weak SHA-256 hashes after upgrades until an admin re-authenticates, which attackers cracked offline at scale. Affected organizations span banking, telecom, healthcare, and critical infrastructure. This is a credential-exposure campaign rather than a single CVE.

Source: BleepingComputer · SecurityWeek

Microsoft attributes Mastra AI npm supply-chain compromise to North Korea’s Sapphire Sleet

Microsoft · June 20, 2026

Microsoft attributed the compromise of more than 140 packages in the @mastra npm scope to the North Korean state actor Sapphire Sleet (BlueNoroff). Attackers hijacked the maintainer account “ehindero” and injected a malicious typosquat dependency, “easy-day-js,” whose post-install hook deployed a cross-platform information stealer targeting credentials, API keys, and 166 cryptocurrency wallet extensions on Windows, Linux, and macOS.

“Microsoft assesses with high confidence that this activity is attributable to Sapphire Sleet, a North Korean state actor that primarily targets the financial sector.” — Microsoft

Source: Microsoft Threat Intelligence · BleepingComputer


This brief covers the trailing ~48 hours (June 22–24, 2026).

Primary sources: Cisco PSIRT (CVE-2026-20230) · SSD Secure · Klue · F5 (CVE-2026-42530 / CVE-2026-42055) · Microsoft Threat Intelligence

Quiet 48 Hours: Oracle PeopleSoft RCE, Microsoft Exchange Zero-Day, and Defender ‘RoguePlanet’ Still Active

This brief covers the trailing ~48 hours (June 18–20, 2026). No new vulnerabilities, advisories, or KEV entries surfaced from authoritative primary sources inside that window — a quiet stretch following last week’s heavy Patch Tuesday cycle. Rather than pad with unverified or stale items, the section below tracks the most significant campaigns from the preceding days that remain active, each presented with its true disclosure date and traced to its primary source.

Still developing

Oracle PeopleSoft zero-day exploited for unauthenticated RCE (CVE-2026-35273)

Oracle Security Alert · June 11, 2026

Oracle issued an out-of-cycle Security Alert for CVE-2026-35273, a critical flaw in PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) carrying a CVSS base score of 9.8. The bug is remotely exploitable without authentication and can result in remote code execution. It was exploited as a zero-day in ShinyHunters data-theft attacks; Mandiant (Google Threat Intelligence) confirmed exploitation and notified more than 100 organizations, 68% of them in the higher-education sector. Oracle released emergency mitigations with a full patch to follow. Not yet listed in CISA KEV at the time of writing.

“This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution.” — Oracle Security Alert advisory

Source: Oracle Security Alert (CPU187) · Mandiant / Google Threat Intelligence · BleepingComputer

Microsoft June Patch Tuesday: Exchange Server zero-day exploited in the wild (CVE-2026-42897)

Microsoft (MSRC) · June 9, 2026

Microsoft’s June 2026 Patch Tuesday addressed 200 flaws, including six zero-days — five publicly disclosed and one exploited in attacks. The actively exploited issue is CVE-2026-42897, a Microsoft Exchange Server spoofing vulnerability affecting Exchange 2016, 2019, and Subscription Edition that lets an attacker execute JavaScript in a target’s browser via Outlook Web Access. The publicly disclosed zero-days include BitLocker bypasses (“YellowKey,” “bitskrieg”) and the “GreenPlasma” and “Mini-Plasma” elevation-of-privilege flaws. Administrators should prioritize the Exchange update.

“Today is Microsoft’s June 2026 Patch Tuesday, with security updates for 200 flaws, including five publicly disclosed zero-day vulnerabilities and one actively exploited in attacks.” — BleepingComputer

Source: Microsoft MSRC advisory (CVE-2026-42897) · BleepingComputer

Microsoft Defender “RoguePlanet” PoC grants SYSTEM on fully patched Windows (no patch)

BleepingComputer / Nightmare Eclipse · June 9, 2026

Hours after Patch Tuesday, the researcher known as Nightmare Eclipse released a proof-of-concept exploit dubbed “RoguePlanet” targeting a Microsoft Defender race-condition flaw. It spawns a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems. No CVE has been assigned and no patch was available at disclosure; Microsoft says it is investigating. Cybersecurity firm ThreatLocker independently reproduced the exploit against fully patched Windows 11 (build with KB5094126). Application allowlisting is cited as an effective mitigation.

“Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described. Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack.” — Danny Jenkins, CEO, ThreatLocker

Source: BleepingComputer

CISA adds Joomla Content Editor flaw to KEV (CVE-2026-48907)

CISA · June 16, 2026

CISA added CVE-2026-48907, an improper access control vulnerability in the Widget Factory Joomla Content Editor (JCE) extension, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The addition sets a remediation deadline for federal civilian agencies under BOD 22-01 and is a strong signal for any organization running the affected Joomla extension to patch or mitigate. KEV status: listed.

Source: CISA alert · CISA KEV catalog


This brief covers the trailing ~48 hours (June 18–20, 2026).

Primary sources:

OpenAI Upgrades ChatGPT Health, Surfaces Rare-Disease Diagnoses, and Brings Grok to Databricks

This brief covers the trailing ~72 hours (June 18–20, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. It was a concentrated window: the verified developments all landed on June 18, led by OpenAI’s health work and xAI’s enterprise expansion.

OpenAI says GPT-5.5 Instant brings frontier-level health responses to free users

OpenAI · June 18, 2026

OpenAI detailed how GPT-5.5 Instant improves ChatGPT’s health and wellness responses, citing better recognition of when urgent care is needed, more context-seeking, and clearer communication of uncertainty. The company says the model now matches its frontier “Thinking” models on its hardest health evaluations, and that the rate of responses flagged for a potential factuality issue in production health traffic fell by 71% over two months. OpenAI notes more than 230 million people ask health and wellness questions on ChatGPT each week.

“On our most challenging health evaluations, GPT-5.5 Instant now performs at a level comparable to our frontier Thinking models. Because it is available to all free users in ChatGPT, more people can benefit from these improvements.” — OpenAI

Source: Improving health intelligence in ChatGPT

An OpenAI reasoning model helps surface 18 new diagnoses in unsolved rare-disease cases

OpenAI · June 18, 2026

In a study published in NEJM AI, researchers from Boston Children’s Hospital’s Manton Center for Orphan Disease Research, Harvard University, and OpenAI used the OpenAI o3 Deep Research model to reanalyze 376 previously unsolved cases. After expert review, additional testing, and clinical confirmation, physicians established diagnoses in 18 cases — an added diagnostic yield of 4.8%. OpenAI emphasizes the model produced evidence-linked hypotheses for specialists to review and did not diagnose any patient or make clinical decisions.

“The bottleneck is time. An expert can devote only so much of their day to any one particular person.” — Dr. Catherine Brownstein, Boston Children’s Hospital’s Manton Center for Orphan Disease Research

Source: Using AI to help physicians diagnose rare genetic diseases affecting children

Grok models go live on Databricks Agent Bricks

xAI · June 18, 2026

Announced alongside the Databricks 2026 Data + AI Summit, Grok models are now natively available on Databricks Agent Bricks, the company’s developer agent platform. The integration lets engineering teams build agents that operate over Lakehouse data alongside other frontier and open-source models in a single governed platform, extending recent availability on Amazon Bedrock.

“We’re excited to share that Grok models are now natively available on Databricks Agent Bricks, Databricks’ developer agent platform.” — xAI

Source: Grok on Databricks

OpenAI adds usage analytics and spend controls for ChatGPT Enterprise

OpenAI · June 18, 2026

OpenAI introduced credit usage analytics and updated spend controls for ChatGPT Enterprise, giving admins a unified view of ChatGPT and Codex consumption across users, products, and models. Admins can now set default workspace limits, configure group-level limits, and create individual overrides, while employees can track usage against their budget and request more credits with context.

“We asked the team at OpenAI to build usage analytics to help find and train-up folks who haven’t adopted Codex, and for granular usage controls to keep spend predictable. These new tools are helping us faster scale productivity of our employees while keeping safeguards in place.” — Ryan Oksenhorn, Co-Founder, Zipline

Source: New usage analytics and updated spend controls for enterprises


This brief covers the trailing ~72 hours (June 18–20, 2026).

Primary sources:

Anthropic Opens Seoul Office; xAI Ships Grok Imagine Video 1.5 and a PowerPoint Add-In

This brief covers the trailing ~72 hours (June 15–18, 2026). Every item below was confirmed against the originating organization’s own announcement page, with a published date inside the window. It was a relatively quiet stretch dominated by xAI shipping product updates and Anthropic expanding internationally.

Anthropic opens a Seoul office and expands across the Korean AI ecosystem

Anthropic · June 17, 2026

Anthropic opened its Seoul office and announced a wave of partnerships across Korean enterprises, startups, and research institutions. Among the deployments named: NAVER has rolled out Claude Code across its entire engineering organization, Samsung SDS is deploying Claude (including Claude Code and Claude Cowork) to employees across Samsung Electronics, and LG CNS is rolling Claude out to thousands of staff. Anthropic also said it will provide Claude access to up to 60 researchers affiliated with Korea’s National AI Research Lab (NAIRL).

“What I see in Korea are teams who understand that innovation and safety are two sides of the same coin. Korean organizations are building with Claude to bring the benefits of AI to millions around the world. Opening an office in Seoul gives a long-term home to our work alongside the people shaping Korean leadership in AI.” — KiYoung Choi, Representative Director of Korea at Anthropic

Source: anthropic.com/news/seoul-office-partnerships-korean-ai-ecosystem

xAI ships Grok Imagine Video 1.5, its best image-to-video model yet

xAI · June 16, 2026

xAI made Grok Imagine Video 1.5 generally available on its Imagine API and rolled out a “Fast” variant on grok.com and the iOS and Android apps. The model generates synchronized audio, speech, and ambience in the same pass as the video, and improves motion and physics consistency. xAI also introduced Projects, parallel multi-agent generation, and library search to the Imagine workflow.

“Grok Imagine Video 1.5 Fast almost doubles generation speed: it produces 6-second, 720p videos in about 25 seconds, down from 40+ seconds in our previous model.” — xAI

Source: x.ai/news/grok-imagine-video-1-5

Grok comes to Microsoft PowerPoint

xAI · June 16, 2026

xAI launched a free Microsoft 365 add-in that runs Grok inside PowerPoint, letting users turn an outline into a full deck, generate individual slides, and restructure sections from a single instruction. The add-in can pull in web and X searches as well as a user’s Grok connectors (such as SharePoint or Google Drive), and companion add-ins for Word and Excel are also available.

“Grok now works inside Microsoft PowerPoint — turn outlines into slides, expand the deck, and tighten the narrative without leaving the app.” — xAI

Source: x.ai/news/introducing-powerpoint-addin

xAI adds an Agent Dashboard to Grok Build

xAI · June 15, 2026

xAI shipped an Agent Dashboard for its Grok Build coding agent that puts every active session on a single screen, sorts them by state so blockers needing input rise to the top, and lets developers peek at output, reply inline, and dispatch new sessions in parallel without losing context. It runs via grok dashboard from the shell or /dashboard inside a session.

“The Agent Dashboard puts every Grok Build session on one screen. See what each is doing, run them in parallel, and step in only when input is needed.” — xAI

Source: x.ai/news/agent-dashboard

Still developing

A notable item that falls just outside the 72-hour window but is worth flagging: on June 10, 2026, Google DeepMind released DiffusionGemma, an experimental open-weights (Apache 2.0) model built on the Gemma 4 architecture that generates text in parallel blocks — denoising up to 256 tokens per step rather than one at a time — for roughly 4x faster single-user generation. Confirmed via Google DeepMind’s announcement and NVIDIA’s optimization post. Source: blog.google.


This brief covers the trailing ~72 hours (June 15–18, 2026).

Primary sources: