[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-cisa-adds-six-new-exploited-cves-to-kev-catalog-in-june":10,"sections":63},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":38,"persona_id":22,"persona_name":22,"section":39,"tags":40,"sources":44,"feedback":62,"feedback_at":22,"cost_usd":62,"total_tokens":62},998,"cisa-adds-six-new-exploited-cves-to-kev-catalog-in-june","CISA Adds Six Actively Exploited Flaws to Vulnerability Catalog","Three June advisories flag active exploitation across Cisco SD-WAN, Android, Linux, LiteLLM, and Check Point, while a new federal directive tightens patching rules.","CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog across three separate advisories in early June, covering products from Cisco and Check Point to Android and an AI proxy tool.\n\nThe additions arrived in three batches. On June 2, CISA flagged an integer overflow in the Android Framework (CVE-2025-48595) and a four-year-old improper authentication flaw in the Linux Kernel (CVE-2022-0492) that is still being actively exploited. The June 8 advisory added a command injection bug in BerriAI's LiteLLM (CVE-2026-42271) and an improper authentication vulnerability in Check Point's Security Gateway (CVE-2026-50751). The June 15 batch covers a path traversal flaw in Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and a symlink-following vulnerability in LiteSpeed's cPanel Plugin (CVE-2026-54420). That last advisory also introduced BOD 26-04, a new federal directive updating the older BOD 22-01: agencies must now prioritize patching on publicly exposed assets where exploitation hands an attacker full system control, and must verify whether a system was already compromised before a patch was applied.\n\nThe LiteLLM entry stands out. It is an open-source proxy that routes API calls to various AI providers, and a command injection flaw in it being actively exploited suggests attackers are now treating AI infrastructure as a target class, not an edge case. BOD 26-04's \"was the system already compromised?\" requirement is also more operationally demanding than anything its predecessor asked for.\n\nCVE-2022-0492, a Linux Kernel flaw from 2022, is a useful reminder that \"old vulnerability\" and \"patched vulnerability\" are not the same thing.","[\"security\",\"cisa\",\"cisco\",\"android\"]","2026-06-02T12:00:00.000Z","2026-06-16T03:08:45.020Z","2026-06-18T13:40:07.012Z","published",null,[24,30,34],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The article misstates the number of CVEs added (claims nine but sources only list six) and mixes CVEs from different advisories without clear attribution; fix the count and ensure each CVE is correctly sourced.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Add a brief concluding paragraph summarizing the June additions and their relevance for federal and private sector vulnerability management.",{"id":35,"reviewer":26,"round":36,"reason":37,"status":29},"editor-r3",3,"Add a concise concluding paragraph that recaps the six June CVEs and explains why they matter for federal and private‑sector vulnerability management.","https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Fcisa-adds-six-new-exploited-cves-to-kev-catalog-in-june.webp","security",[39,41,42,43],"cisa","cisco","android",[45,48,50,52,54,56,58,60],{"name":46,"url":47},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F06\u002F15\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":49},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F06\u002F08\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":51},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F06\u002F02\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":53},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F06\u002F25\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":55},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F10\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":57},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F15\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":59},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F22\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",{"name":46,"url":61},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F27\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog",0,{"sections":64},[65,70,74,79,84,89,94,99,104,109,114,119,124,129],{"name":66,"slug":67,"count":68,"latest_published_at":69},"AI","ai",2602,"2026-07-18T18:30:00.000Z",{"name":71,"slug":39,"count":72,"latest_published_at":73},"Security",315,"2026-07-17T19:30:00.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Policy","policy",169,"2026-07-17T19:49:53.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Hardware","hardware",126,"2026-07-16T20:09:48.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"Consumer Tech","consumer-tech",94,"2026-07-16T16:29:46.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Software","software",72,"2026-07-17T09:42:05.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"Science","science",66,"2026-07-10T10:29:37.000Z",{"name":105,"slug":106,"count":107,"latest_published_at":108},"Dev Tools","dev-tools",60,"2026-07-16T16:59:13.000Z",{"name":110,"slug":111,"count":112,"latest_published_at":113},"Startups","startups",42,"2026-07-16T16:30:35.000Z",{"name":115,"slug":116,"count":117,"latest_published_at":118},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":120,"slug":121,"count":122,"latest_published_at":123},"General","general",29,"2026-07-10T22:28:58.000Z",{"name":125,"slug":126,"count":127,"latest_published_at":128},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":130,"slug":131,"count":132,"latest_published_at":133},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]