Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Cisco tops a five-vendor KEV batch

2 min read
18:20UTC

CISA drew two more Cisco flaws into its catalogue this fortnight, alongside a SimpleHelp bypass that reopens the managed-service-provider route used by DragonForce in 2025.

TechnologyDeveloping
Key takeaway

Cisco tops the KEV catalogue with five entries since April across three separate product lines.

CISA cleared two Known Exploited Vulnerabilities (KEV) batches this fortnight. On Thursday 25 June, due 28 June, it listed a Cisco Unified Communications Manager server-side request forgery (SSRF) flaw, CVE-2026-20230, and a flaw in PTC Windchill, CVE-2026-12569, allowing unauthenticated remote code execution (RCE). On Monday 29 June, due 2 July, came a SimpleHelp single-sign-on (SSO) authentication bypass, CVE-2026-48558, a Cisco Catalyst SD-WAN Manager path traversal, CVE-2026-20262, and a Joomla Widget Factory flaw, CVE-2026-48907. 1

That makes Cisco the most repeat-listed vendor on this beat, with five KEV entries across three product lines since April, following the CVSS-10 Catalyst flaw that the UAT-8616 group was already exploiting in May . An SSRF flaw lets an attacker make a server issue requests on their behalf, reaching systems the attacker cannot touch directly. SimpleHelp is the remote monitoring and management (RMM) tool tied to the 2025 DragonForce campaign against managed service providers (MSPs), and an SSO bypass re-opens the same one-to-many route into every downstream client.

PTC Windchill sits in the product-lifecycle-management (PLM) systems that aerospace, automotive and defence suppliers use to hold engineering data. An unauthenticated RCE there is a supply-chain entry rather than a perimeter one: the attacker needs no credential, and the prize is the design data a supplier holds on behalf of its customers.

Deep Analysis

In plain English

Managed service providers, or MSPs, are companies that IT departments hire to remotely manage computers for lots of different clients at once, often using a tool called SimpleHelp. A newly listed flaw lets an attacker skip the login step in SimpleHelp, which matters because whoever controls that one tool can potentially reach every client the MSP looks after. Cisco and the website-building tool Joomla also had flaws added to the same must-fix list this fortnight. The common thread is that all five bugs let an attacker either break into a network from outside or move around inside it once they are in, and criminals often buy and sell working exploits for bugs like these rather than write their own.

Deep Analysis
Root Causes

SimpleHelp, like most remote monitoring and management tools built for MSPs, runs on a one-to-many trust model: a single administrator credential on the server can push software to every client endpoint it manages, which is exactly the feature ransomware crews weaponise once they compromise the server itself.

Cisco's Catalyst SD-WAN Manager path-traversal flaw follows the same access-broker pattern already logged against Cisco SD-WAN infrastructure through the UAT-8616 cluster: a criminal broker validates access into edge network-management consoles, then resells it to whichever ransomware affiliate pays first, rather than exploiting the flaw directly.

What could happen next?
  • Risk

    Any MSP running a self-hosted, internet-reachable SimpleHelp instance faces a Kaseya-scale downstream exposure if the SSO bypass is exploited before patching, since one compromised server reaches every managed client.

  • Consequence

    Cisco's repeated appearance in KEV batches this fortnight, alongside the SD-WAN Manager flaw already tied to the UAT-8616 broker network, suggests the same access-broker group may be scouting or reselling access to this new path-traversal bug.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Causes and effects
This Event
Cisco tops a five-vendor KEV batch
A repeat run of Cisco flaws and a SimpleHelp bypass put both vendor concentration and the managed-service-provider supply chain back on defenders' radar.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.