Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Cisco tops a five-vendor KEV batch

2 min read
16:08UTC

CISA drew two more Cisco flaws into its catalogue this fortnight, alongside a SimpleHelp bypass that reopens the managed-service-provider route used by DragonForce in 2025.

TechnologyDeveloping
Key takeaway

Cisco tops the KEV catalogue with five entries since April across three separate product lines.

CISA cleared two Known Exploited Vulnerabilities (KEV) batches this fortnight. On Thursday 25 June, due 28 June, it listed a Cisco Unified Communications Manager server-side request forgery (SSRF) flaw, CVE-2026-20230, and a flaw in PTC Windchill, CVE-2026-12569, allowing unauthenticated remote code execution (RCE). On Monday 29 June, due 2 July, came a SimpleHelp single-sign-on (SSO) authentication bypass, CVE-2026-48558, a Cisco Catalyst SD-WAN Manager path traversal, CVE-2026-20262, and a Joomla Widget Factory flaw, CVE-2026-48907. 1

That makes Cisco the most repeat-listed vendor on this beat, with five KEV entries across three product lines since April, following the CVSS-10 Catalyst flaw that the UAT-8616 group was already exploiting in May . An SSRF flaw lets an attacker make a server issue requests on their behalf, reaching systems the attacker cannot touch directly. SimpleHelp is the remote monitoring and management (RMM) tool tied to the 2025 DragonForce campaign against managed service providers (MSPs), and an SSO bypass re-opens the same one-to-many route into every downstream client.

PTC Windchill sits in the product-lifecycle-management (PLM) systems that aerospace, automotive and defence suppliers use to hold engineering data. An unauthenticated RCE there is a supply-chain entry rather than a perimeter one: the attacker needs no credential, and the prize is the design data a supplier holds on behalf of its customers.

Deep Analysis

In plain English

Managed service providers, or MSPs, are companies that IT departments hire to remotely manage computers for lots of different clients at once, often using a tool called SimpleHelp. A newly listed flaw lets an attacker skip the login step in SimpleHelp, which matters because whoever controls that one tool can potentially reach every client the MSP looks after. Cisco and the website-building tool Joomla also had flaws added to the same must-fix list this fortnight. The common thread is that all five bugs let an attacker either break into a network from outside or move around inside it once they are in, and criminals often buy and sell working exploits for bugs like these rather than write their own.

Deep Analysis
Root Causes

SimpleHelp, like most remote monitoring and management tools built for MSPs, runs on a one-to-many trust model: a single administrator credential on the server can push software to every client endpoint it manages, which is exactly the feature ransomware crews weaponise once they compromise the server itself.

Cisco's Catalyst SD-WAN Manager path-traversal flaw follows the same access-broker pattern already logged against Cisco SD-WAN infrastructure through the UAT-8616 cluster: a criminal broker validates access into edge network-management consoles, then resells it to whichever ransomware affiliate pays first, rather than exploiting the flaw directly.

What could happen next?
  • Risk

    Any MSP running a self-hosted, internet-reachable SimpleHelp instance faces a Kaseya-scale downstream exposure if the SSO bypass is exploited before patching, since one compromised server reaches every managed client.

  • Consequence

    Cisco's repeated appearance in KEV batches this fortnight, alongside the SD-WAN Manager flaw already tied to the UAT-8616 broker network, suggests the same access-broker group may be scouting or reselling access to this new path-traversal bug.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Causes and effects
This Event
Cisco tops a five-vendor KEV batch
A repeat run of Cisco flaws and a SimpleHelp bypass put both vendor concentration and the managed-service-provider supply chain back on defenders' radar.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.