VYPR
AI Brief2026-06-17· generated Jun 17, 2026

CISA Adds LiteSpeed and Exchange Flaws to KEV

CISA flags a LiteSpeed cPanel plugin and Microsoft Exchange zero-day as actively exploited, while SimpleHelp RMM and 25 WordPress plugin flaws pile on.

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog today, including a LiteSpeed cPanel plugin flaw and a Microsoft Exchange Server spoofing bug. The LiteSpeed issue (CVE-2026-54420) allows a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS to escalate privileges via symlink mishandling in the LiteSpeed cPanel plugin before version 2.4.8. As BleepingComputer reported, this is the second cPanel plugin flaw added to KEV in recent months, and The Hacker News noted that attackers are actively exploiting it for root privilege escalation on shared hosting environments. SecurityWeek and Cyber Security News both confirmed wild exploitation, making this an urgent patch for any hosting provider using LiteSpeed WHM PlugIn versions prior to 5.3.2.0.

Microsoft Exchange Server is under active attack via CVE-2026-42897, a cross-site scripting vulnerability that allows an unauthenticated attacker to perform spoofing over a network. BleepingComputer reported that Microsoft patched this zero-day as part of its June 2026 Patch Tuesday, which fixed over 200 flaws including six zero-days. Dark Reading and SecurityWeek both covered the exploitation timeline, noting that the vulnerability was being used in the wild before a patch was available. The flaw affects on-premises Exchange Server deployments and was added to CISA KEV, as CISA confirmed. Organizations still running on-prem Exchange should prioritize this patch given the active exploitation and the sensitive nature of email infrastructure.

A critical authentication bypass in SimpleHelp remote monitoring and management (RMM) software (CVE-2026-48558) puts nearly 14,000 exposed servers at risk of full compromise. The flaw affects SimpleHelp versions 5.5.15 and prior, as well as 6.0 pre-release builds, and allows attackers to bypass OIDC authentication by submitting identity tokens without proper validation. Help Net Security explained that an attacker can forge tokens to create rogue remote support accounts, effectively gaining full administrative access to managed endpoints. BleepingComputer noted that this gives attackers persistent backdoor access to every device managed by the compromised SimpleHelp instance. With Cyber Security News reporting thousands of exposed servers, organizations using SimpleHelp should immediately upgrade or disable OIDC authentication until patched.

A massive wave of 25 WordPress plugin vulnerabilities was disclosed in a single day, with 11 rated critical and many allowing unauthenticated remote code execution or PHP object injection. The most severe include CVE-2026-48836 (Easy Invoice, CVSS 10.0, unauthenticated RCE), CVE-2026-40772 (GeekyBot, CVSS 10.0, arbitrary file upload), and CVE-2026-52704 (WooCommerce PDF Invoice Builder, CVSS 10.0, code injection). A cluster of PHP object injection flaws affects popular form and marketing integrations: CVE-2026-9691 (ActiveCampaign integration), CVE-2026-49765 (Mailchimp integration), CVE-2026-49763 (HubSpot integration), CVE-2026-49109 (Salesforce integration), and CVE-2026-49781 (OttoKit), all rated CVSS 9.8 and exploitable without authentication. As Vypr Intelligence detailed, the Wordfence weekly report also highlighted CVE-2026-49766 (WP User Manager, CVSS 9.9) which allows subscriber-level arbitrary file deletion, and CVE-2026-49764 (RegistrationMagic, CVSS 9.8) enabling unauthenticated authentication bypass. Site administrators should audit their plugin inventories immediately.

A critical vulnerability in Spring Data Commons (CVE-2018-1273) was added to CISA KEV, despite being disclosed eight years ago. The flaw carries a CVSS score of 9.8 and an EPSS of 0.96, indicating near-certain exploitation. Versions prior to 1.13.11 and 2.0.6 are affected by a property binder vulnerability that allows unauthenticated remote code execution. While this is an older CVE, its addition to KEV signals that attackers are actively targeting unpatched Spring Data Commons deployments, likely in Java-based enterprise applications. Organizations should verify they are running patched versions, as the widespread use of Spring in corporate environments makes this a high-value target for threat actors.

A critical flaw in UDS Identity Config (CVE-2026-46389) exposes Keycloak deployments used in UDS Core's identity infrastructure. Versions 0.11.0 through 0.26.0 contain a logic error in the client-kubernetes-secret Keycloak client that could allow unauthorized access to identity configuration. The vulnerability carries a CVSS score of 10.0, reflecting the severity of compromising identity and access management infrastructure. Organizations using UDS Core for Kubernetes identity management should upgrade to the latest version immediately, as a compromised Keycloak instance could lead to complete cluster compromise through forged authentication tokens and unauthorized access to protected services.

Synthesized by Vypr AI
CISA Adds LiteSpeed and Exchange Flaws to KEV · VYPR