Monthly exploitation report · June 2026

Known Exploited Vulnerabilities Report — June 2026

Monthly analysis of new exploited vulnerabilities added to KEVIntel and exploitation attempts observed by sensors.

804
KEVs added

794 were outside CISA KEV when added

6,046
Exploitation events
72.1%
Top-five concentration

Share of events tied to five CVEs

1.1 days
Median CISA lead

Across 294 CVEs added by KEV Intelligence first

Executive brief

The month in three decisions

01

Validate exposure against the top five

Five CVEs produced 72.1% of June events. Prioritize asset discovery and remediation around Sentry, ThinkPHP Framework, Splunk Enterprise, PeopleSoft Enterprise PeopleTools, and Cisco Unified Communications Manager.

02

Do not rely on CISA KEV alone

KEV Intelligence added 794 exploited CVEs outside CISA KEV during June; 537 were still absent at month-end.

03

Treat telemetry as directional evidence

Event volume and source breadth help identify pressure, but observations do not prove that a real-world target was compromised or represent all exploitation activity worldwide.

Exploitation activity

Observed exploitation remained concentrated

KEV Intelligence sensors recorded 6,046 exploitation events in June. A small set of vulnerabilities drove most of the observed volume.

Observed exploitation events

May versus June 2026

May
0
June
6,046

64

CVEs observed

812

Source IPs

65

First observed

Concentration of observed events

Top vulnerability 38.9%
Top five 72.1%
Top ten 83.3%

For CISOs, this concentration supports a focused exposure-validation and remediation sprint rather than treating every observed CVE as equally urgent.

Visibility before CISA KEV

KEV Intelligence was earlier on 294 vulnerabilities

294 vulnerabilities were added by KEV Intelligence before later inclusion in CISA KEV. The median lead time was 1.1 days; the longest was 6430.7 days.

1.1 days

Median positive lead

537

Still absent at month-end

Most targeted

The vulnerabilities driving June activity

Ranked by sensor-observed exploitation events. Event volume shows intensity; unique source IPs help indicate breadth.

1
CVE-2026-10520

ivanti · Sentry

In CISA KEV

38.9% of monthly events

Events
2,351
Source IPs
118
2
CVE-2022-47945

ThinkPHP · ThinkPHP Framework

Outside CISA KEV at month-end

10.5% of monthly events

Events
634
Source IPs
174
3
CVE-2026-20253

Splunk · Splunk Enterprise

In CISA KEV

9.9% of monthly events

Events
601
Source IPs
52
4
CVE-2026-35273

Oracle Corporation · PeopleSoft Enterprise PeopleTools

In CISA KEV

8.4% of monthly events

Events
510
Source IPs
70
5
CVE-2026-20230

Cisco · Cisco Unified Communications Manager

In CISA KEV

4.4% of monthly events

Events
264
Source IPs
20
6
CVE-2025-55182

Meta · react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

In CISA KEV

3.2% of monthly events

Events
194
Source IPs
48
7
CVE-2014-2383

dompdf · dompdf

Outside CISA KEV at month-end

2.8% of monthly events

Events
170
Source IPs
68
8
CVE-2026-4020

RocketGenius · Gravity SMTP

Outside CISA KEV at month-end

1.8% of monthly events

Events
109
Source IPs
102
9
CVE-2017-18368

ZyXEL · P660HN-T1A v1 TCLinux Fw

In CISA KEV

1.8% of monthly events

Events
108
Source IPs
29
10
CVE-2021-41773

Apache Software Foundation · Apache HTTP Server

In CISA KEV

1.5% of monthly events

Events
93
Source IPs
71

Vendor exposure

Newly added KEVs by vendor

Microsoft

33 outside CISA KEV when added

33

Cisco

25 outside CISA KEV when added

26

D-Link

16 outside CISA KEV when added

16

Google

15 outside CISA KEV when added

15

Fortinet

14 outside CISA KEV when added

14

Weakness patterns

Most common CWE classes

CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Most common newly added weakness

92

CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

79 newly added KEVs

79

CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

77 newly added KEVs

77

CWE-434 · Unrestricted Upload of File with Dangerous Type

38 newly added KEVs

38

CWE-287 · Improper Authentication

37 newly added KEVs

37

51.7%

Critical severity

625

Public PoC references

562

Nuclei references

64

Observed request paths

Methodology and limitations

How to interpret and cite this report

These notes define the reporting window, what sensor observations mean, and where the dataset should not be generalized.

Full KEV Intelligence methodology
Reporting period

Reporting period is 2026-06-01 00:00:00 UTC through 2026-06-30 23:59:59 UTC.

Sensor scope

KEVIntel sensor telemetry represents activity observed by the KEVIntel sensor network. It does not represent all exploitation activity occurring globally.

Interpretation

An observed exploitation attempt does not by itself demonstrate that a real-world target was successfully compromised.

CISA status

CISA KEV status at month-end is reconstructed from stored CISA addition dates (additive only; removals are not tracked).

Source-IP coverage

Historical or backfilled KEV records cannot be identified reliably from existing fields and are not listed as a separate category.

Prefer deep links to individual CVE reports and this methodology when citing sensor-observed vulnerabilities.

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.