Known Exploited Vulnerabilities Report: June 2026

A monthly snapshot of known exploited vulnerabilities tracked by KEVIntel during June 2026 — beyond-CISA coverage, sensor-observed exploitation, and vendor concentration — for journalists, vulnerability-management teams, and researchers.

Published 1 July 2026 · Permanent URL: https://kevintel.com/research/known-exploited-vulnerabilities-report/2026/06

Total KEVs

2,694

Beyond CISA KEV

1,038

Exploitation Events (June 2026)

6,046

Unique Attacker IPs (June 2026)

812

Report Highlights

  • Beyond-CISA KEV counts and catalog totals from the KEVIntel feed
  • Sensor exploitation attempts and unique attacker IPs for the report month
  • Most-targeted CVEs and KEVs added during the month
  • Methodology notes and citation guidance for reuse

Catalog Snapshot

As of publication, KEVIntel tracks 2,694 known exploited vulnerabilities, including 1,038 not currently listed in the official CISA KEV catalog. CISA KEV remains the authoritative U.S. government baseline; KEVIntel complements it with additional attestations, enrichment, RSS delivery, and proprietary sensor telemetry.

Sensor-Observed Exploitation

KEVIntel sensors observe exploitation attempts against internet-facing services and map activity to CVEs where signals are sufficiently specific. Counts are not proof of compromise of a particular organisation. Figures below cover June 2026 (1 Jun–30 Jun 2026).

Exploitation Activity — June 2026

Loading...

Daily exploitation attempts observed by KEVIntel sensors during June 2026. Not confirmed compromise.

Most Targeted

CVEs with the most sensor-observed exploitation attempts in June 2026.

CVE Confidence CISA KEV Attempts Artifacts

Sentry

Confirmed In CISA 2,351
PoC Nuclei VPatch

ThinkPHP Framework

Confirmed Not in CISA 634
PoC Nuclei VPatch

Splunk Enterprise

Confirmed In CISA 601
PoC Nuclei VPatch

PeopleSoft Enterprise PeopleTools

Confirmed In CISA 510
PoC Nuclei VPatch

Cisco Unified Communications Manager

Confirmed In CISA 264
PoC VPatch

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Confirmed In CISA 194
PoC Nuclei

dompdf

Confirmed Not in CISA 170
PoC Nuclei

Gravity SMTP

Confirmed Not in CISA 109
PoC Nuclei VPatch

P660HN-T1A v1 TCLinux Fw

Confirmed In CISA 108
PoC VPatch

Apache HTTP Server

Confirmed In CISA 93
PoC Nuclei

FortiSandbox, FortiSandbox PaaS

Confirmed In CISA 83
PoC Nuclei VPatch

DotNetNuke CMS Fixed in 9.1.1

Confirmed In CISA 78
PoC Nuclei

BIG-IP

Confirmed In CISA 57
PoC Nuclei

gogs

Confirmed Not in CISA 54
PoC VPatch

FortiSandbox, FortiSandbox Cloud

Confirmed Not in CISA 47
PoC VPatch

WebLogic Server

Confirmed In CISA 44
PoC Nuclei VPatch

Apache Flink

Confirmed Not in CISA 37
PoC Nuclei

GPON home routers

Confirmed In CISA 37
PoC Nuclei VPatch

DGN1000

Confirmed Not in CISA 36
VPatch

TP-Link Archer AX21 (AX1800)

Confirmed In CISA 34
PoC Nuclei Nessus VPatch

Elasticsearch

Confirmed In CISA 33
PoC Nuclei

WebLogic Server

Confirmed In CISA 29
PoC Nuclei VPatch

WooCommerce Help Scout

Confirmed Not in CISA 26
PoC Nuclei

dotCMS Core

Confirmed Not in CISA 25
PoC Nuclei VPatch

NetWeaver Application Server Java

Confirmed In CISA 24
PoC Nuclei Nessus VPatch

KEVs Added This Month

Primary known exploited vulnerabilities first attested on KEVIntel in June 2026 (804 total).

CVE Confidence CISA KEV Sensors Added Artifacts

gogs

Confirmed Not in CISA Yes 30 days ago
PoC VPatch

Oracle Payments

Confirmed In CISA Yes about 1 month ago
PoC VPatch

SimpleHelp

Confirmed In CISA about 1 month ago
PoC

dotCMS Core

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

LearnPress – WordPress LMS Plugin

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei

Windchill PDMLink, FlexPLM

Confirmed In CISA about 1 month ago

Cisco Unified Communications Manager

Confirmed In CISA Yes about 1 month ago
PoC VPatch

EDS5000

Confirmed In CISA about 1 month ago

Apache OFBiz

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

Gravity SMTP

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

TRUfusion Enterprise

High Not in CISA about 1 month ago
PoC Nuclei

Repetier Server

High Not in CISA about 1 month ago
PoC Nuclei

Restler

High Not in CISA about 1 month ago
PoC Nuclei

Boa Web Server

High Not in CISA about 1 month ago
PoC Nuclei

CyberPower PowerPanel Enterprise

High Not in CISA about 1 month ago
PoC Nuclei

CuppaCMS

High Not in CISA about 1 month ago
PoC Nuclei

E2000

High Not in CISA about 1 month ago
PoC Nuclei

datacube3

High Not in CISA about 1 month ago
PoC Nuclei

PHP-Fusion

High Not in CISA about 1 month ago
PoC Nuclei

CuppaCMS

High Not in CISA about 1 month ago
PoC Nuclei

Joomla Content Editor (JCE) extension for Joomla

Confirmed In CISA about 1 month ago
PoC Nuclei

FortiSandbox, FortiSandbox Cloud

Confirmed Not in CISA Yes about 1 month ago
PoC VPatch

WBCE CMS

High Not in CISA about 1 month ago
PoC Nuclei

Cisco Catalyst SD-WAN Manager

Confirmed In CISA about 1 month ago
PoC

Apache Struts

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

Jenkins

High Not in CISA about 2 months ago
PoC

Splunk Enterprise

Confirmed In CISA Yes about 2 months ago
PoC Nuclei VPatch

Cuppa CMS

High Not in CISA about 2 months ago
PoC Nuclei

cPanel Plugin

Confirmed In CISA about 2 months ago
PoC

SAP NetWeaver AS JAVA (LM Configuration Wizard)

Confirmed Not in CISA Yes about 2 months ago
PoC VPatch

FortiSandbox, FortiSandbox PaaS

Confirmed In CISA Yes about 2 months ago
PoC Nuclei VPatch

PeopleSoft Enterprise PeopleTools

Confirmed In CISA Yes about 2 months ago
PoC Nuclei VPatch

UpdraftPlus: WP Backup & Migration Plugin

High Not in CISA about 2 months ago
PoC

Case Theme User

High Not in CISA about 2 months ago

langflow

Confirmed Not in CISA Yes about 2 months ago
PoC Nuclei

Sentry

Confirmed In CISA Yes about 2 months ago
PoC Nuclei VPatch

E2 Series, Encoder G-Code

High Not in CISA about 2 months ago
PoC Nuclei

Ditty

High Not in CISA about 2 months ago
PoC Nuclei

traccar

High Not in CISA about 2 months ago
PoC Nuclei

Chrome

Confirmed In CISA about 2 months ago
PoC

UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial

Confirmed In CISA Yes about 2 months ago
PoC Nuclei VPatch

UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial

Confirmed In CISA about 2 months ago

UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial

Confirmed In CISA about 2 months ago
PoC

Yaws

High Not in CISA about 2 months ago
PoC Nuclei

Binatone Hubble Cameras

High Not in CISA about 2 months ago
PoC Nuclei

WebIQ

High Not in CISA about 2 months ago
PoC Nuclei

WP Job Portal

High Not in CISA about 2 months ago
PoC Nuclei

RAX43

High Not in CISA about 2 months ago

go-ibax

High Not in CISA about 2 months ago

Grafana

High Not in CISA about 2 months ago
PoC Nuclei

Showing 50 of 804 KEVs first attested this month. Browse the live feed.

Vendors and Products

Vendors with the most known exploited vulnerabilities first attested on KEVIntel in June 2026. Where a vendor hub exists, open it for catalog context; otherwise filter the live feed by vendor.

Methodology and Data Access

Attestation rules, confidence scoring, and sensor definitions are documented in the methodology. Consume the catalog via RSS and API (registration required for tokens). There is no free catalog CSV; Enterprise attacker-intelligence CSV is a separate export.

All research and data · Prefer deep links when citing sensor-observed CVEs or methodology.