Check Point VPN Bypass Leads KEV Wave
CISA flags a Check Point VPN auth bypass tied to ransomware and a Fortinet FortiAnalyzer flaw, as Microsoft patches a record 206 CVEs and Ivanti Sentry comes under active attack.

CISA adds four actively exploited flaws to KEV, including a Check Point VPN auth bypass tied to ransomware. CVE-2026-50751 (CVSS 9.3) is a logic-flow weakness in the deprecated IKEv1 key exchange in Check Point Remote Access and Mobile Access VPNs that lets an unauthenticated attacker bypass user authentication and establish a VPN tunnel without valid credentials. CISA confirmed active exploitation in ransomware campaigns, as Cyber Security News reported. Separately, CVE-2026-24858 (CVSS 9.8) is an authentication bypass in Fortinet FortiAnalyzer that allows an unauthenticated attacker to gain administrative access via an alternate path or channel. Fortinet has released patches for all affected versions. CVE-2026-11645 (CVSS 8.8) is a V8 out-of-bounds read/write in Google Chrome that was exploited as a zero-day in the wild — the fifth Chrome zero-day of 2026, as The Register noted. CVE-2026-20245 (CVSS 7.8) is a local privilege escalation in the CLI of Cisco Catalyst SD-WAN Controller, Manager, and Validator that allows an authenticated local attacker to gain root access; Cisco has not yet released a patch, as CyberScoop reported.
Microsoft's June 2026 Patch Tuesday fixes a record 206 CVEs, including three zero-days and critical RCEs across Azure Stack Edge, DHCP Client, and Nuance PowerScribe. CVE-2026-47643 (CVSS 9.8) is an external control of file name or path in Azure Stack Edge that allows unauthenticated remote code execution over the network. CVE-2026-44815 (CVSS 9.8) is a stack-based buffer overflow in the Windows DHCP Client that similarly enables unauthenticated network-based RCE. CVE-2026-26142 (CVSS 9.8) is a deserialization-of-untrusted-data flaw in Nuance PowerScribe that allows remote code execution. CVE-2026-47281 (CVSS 9.6) is an improper input validation in Visual Studio Code that allows privilege escalation over the network. CVE-2025-10263 (CVSS 9.1) affects Arm processors (Cortex and Neoverse families) and was patched by Microsoft as part of the June update. As BleepingComputer reported, three of the 206 flaws were actively exploited zero-days at the time of release. Organizations should prioritize the DHCP Client and Azure Stack Edge patches given their network-based, pre-auth attack vectors.
Ivanti Sentry is hit with two critical pre-auth vulnerabilities — one a max-severity 10.0 — with active exploitation following public PoC release. CVE-2026-10523 (CVSS 9.9) is an authentication bypass that allows a remote unauthenticated attacker to create arbitrary administrative accounts and gain full administrative access. As The Register detailed, the companion flaw CVE-2026-10520 (CVSS 10.0) is a pre-auth OS command injection that allows root-level remote code execution. watchTowr Labs published a technical deep-dive demonstrating exploitation, and Rapid7 confirmed that attacks began shortly after the PoC release. Ivanti has released patches in versions R10.5.2, R10.6.2, and R10.7.1. Any organization running Ivanti Sentry should treat this as an emergency patching event.
Fortinet FortiSandbox ships a critical OS command injection fix alongside the FortiAnalyzer KEV entry. CVE-2026-25089 (CVSS 9.8) is an improper neutralization of special elements used in an OS command in FortiSandbox that allows an unauthenticated attacker to execute arbitrary commands on the appliance. Affected versions include FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and 4.2 all versions, as well as FortiSandbox Cloud 5.0.0 through 5.0.5. SecurityWeek reported that Fortinet has released patches for all affected versions. Given that FortiSandbox is often deployed in security-critical inspection pipelines, a full compromise of the appliance could allow attackers to blind detection systems and tamper with sandbox analysis results.
Google patches two additional Chrome critical flaws beyond the V8 zero-day, including a sandbox escape via Drag and Drop on Android. CVE-2026-11638 (CVSS 9.6) is a use-after-free in Printing that could allow a sandbox escape via a crafted HTML page. CVE-2026-11029 (CVSS 9.6) is an insufficient validation of untrusted input in Drag and Drop on Android that similarly enables sandbox escape after compromising the renderer process. Both were fixed in Chrome 149.0.7827.103 alongside the actively exploited CVE-2026-11645. As The Hacker News noted, the V8 zero-day was the fifth Chrome zero-day exploited in the wild this year, underscoring the persistent targeting of the browser's JavaScript engine.
A wave of critical vulnerabilities hits edge devices, open-source CMS platforms, and healthcare software. CVE-2026-10045 (CVSS 9.8) affects Shenzhen Kangda Xin DR300 routers (version 2.1.2.121) with hardcoded credentials and telnet enabled by default on WAN and LAN interfaces, allowing full device takeover. CVE-2026-38615 (CVSS 9.8) is a command execution flaw in DedeCMS V5.7.118's file_manage_control.php. CVE-2026-36721 (CVSS 9.8) is a JWT signature verification bypass in Bookcars v8.3 that allows authentication bypass via forged tokens. CVE-2026-8025 (CVSS 9.8) is a SQL injection in MOSK CBS Platform through June 9, 2026. CVE-2026-11429 (CVSS —, Critical) affects Altium Enterprise Server and Altium 365, where unvalidated file uploads in the Vault Service ScriptsController allow arbitrary file writes. CVE-2026-11362 (CVSS 9.8) is a metric injection in the Perl DataDog::DogStatsD library through version 0.07. CVE-2026-34691 (CVSS 9.3) is a stored XSS in Adobe Experience Manager Forms JEE (versions up to 6.5.24.0 and LTS SP1). These vulnerabilities span consumer routers, enterprise CMS, healthcare dictation software, and PCB design platforms, reflecting the breadth of today's threat landscape.
Arm discloses a critical vulnerability affecting a wide range of Cortex and Neoverse processors. CVE-2025-10263 (CVSS 9.1) impacts Arm C1-Ultra, C1-Premium, Neoverse V3, V3AE, V2, V1, N2, N1, Cortex-X925, X4, X3, X2, X1, X1C, A710, A78, A78AE, A78C, A77, A76, and A76A processors. While the specific attack vector is not fully detailed in the bundle, the broad processor coverage and critical severity rating make this a significant supply-chain concern for cloud providers and device manufacturers. Microsoft addressed this vulnerability in its June 2026 Patch Tuesday release, as The Hacker News reported.