June 2026 CVE Landscape
Insikt Group identified 60 high-impact vulnerabilities in June 2026 (a 49% increase from May), with 23 listed in CISA's KEV catalog and 53 having public PoC exploits. The dominant theme was exploitation of externally reachable enterprise applications and appliances by multiple threat actors: StrikeShark chained 13 CVEs to deploy SharkLoader and Cobalt Strike, Lazarus exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT, APT36 targeted India via Microsoft Office/Windows CVEs, and Qilin ransomware was linked to Check Point gateway exploitation. 25 of the 60 vulnerabilities enabled RCE across 18 vendors, with CWE-22 (Path Traversal) being the most common flaw class.
Detection / Hunteropenrouter
What Happened
In June 2026, security researchers identified 60 serious software vulnerabilities that organizations should fix urgently, a nearly 50% increase from the previous month. Hackers are actively exploiting many of these flaws in widely used products from Microsoft, Cisco, Fortinet, Google, and others. Multiple criminal and nation-state groups are using these vulnerabilities to break into organizations: one group called StrikeShark chained together over a dozen separate vulnerabilities to gain deep access, while North Korea's Lazarus Group exploited a critical flaw in popular web development software to install spyware. Organizations using any of the affected products should prioritize patching, especially for vulnerabilities listed in the government's Known Exploited Vulnerabilities catalog. Security teams should also verify that internet-facing systems are updated, as attackers are primarily targeting externally reachable applications and devices.
Key Takeaways
- 60 high-impact vulnerabilities identified in June 2026, a 49% increase from May; 30 scored Very Critical on the Recorded Future Risk Score
- 23 of 60 vulnerabilities are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active in-the-wild exploitation
- StrikeShark campaign chained 13 CVEs across multiple vendors (Microsoft, Fortinet, Cisco, Hikvision, F5, Zimbra, GeoServer, Apache) to deploy SharkLoader and deliver Cobalt Strike
- Lazarus Group exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT against financial and blockchain organizations via dependency confusion and compromised PoC code
- 25 of 60 vulnerabilities enabled remote code execution across 18 vendors; 53 of 60 had public proof-of-concept exploits available
- Nuclei templates created by Insikt Group for CVE-2026-35616 (FortiClient EMS) and CVE-2026-25939 (Frangoteam FUXA), available to Recorded Future customers
Affected Systems
- Microsoft Windows 10/11, Windows Server 2012/2019, Exchange Server 2013/2016/2019, SharePoint, Microsoft 365 Apps, Office 2016, Defender Antimalware Platform, Malware Protection Engine
- Fortinet FortiClient EMS, FortiOS, FortiProxy, FortiSwitchManager, FortiSandbox PaaS/Cloud
- Cisco Unified Communications Manager, Catalyst SD-WAN Manager/Controller, IOS XE Software
- Ubiquiti UniFi OS, UniFi OS Server, UDM, UDM-Pro, Express 7
- Linux Kernel, Android Framework, DD-WRT Firmware
- Google Chromium V8 and Chrome
- Oracle PeopleSoft Enterprise PeopleTools, WebLogic Server, Payments
- Splunk Enterprise, SolarWinds Serv-U, Veeam Backup and Replication
- Check Point Security Gateway, Quantum Security Gateway, Spark Firewalls
- Meta React Server Components / Next.js
- WinRAR, Apache Shiro, Openfire, F5 BIG-IP, GeoServer, Zimbra, Joomla JCE, PTC Windchill, SimpleHelp, BerriAI LiteLLM, Langflow, Arista EOS, Lantronix EDS5000, Hikvision Firmware, LiteSpeed cPanel Plugin, WPEverest Everest Forms Pro, Mirasvit Full Page Cache Warmer, Gravity SMTP, Kirki Page Builder, Frangoteam FUXA
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2020-17103 | Microsoft Windows 10/11 and Windows Server 2019 | Critical | Actively exploited vulnerability in Microsoft Windows with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2022-0492 | Linux Kernel | Critical | Actively exploited Linux Kernel vulnerability with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2025-55182 | Meta React Server Components / Next.js | Critical | React2Shell vulnerability (CVSS v3.1 10.0) exploited by Lazarus Group to deploy COPPERHEDGE and EtherRAT via dependency confusion and compromised PoC code; enables persistent C2 and data exfiltration; listed in CISA KEV. |
| CVE-2025-67038 | Lantronix EDS5000 | Critical | Actively exploited vulnerability in Lantronix EDS5000 with risk score 99; listed in CISA KEV. |
| CVE-2025-8088 | WinRAR | Critical | Actively exploited RCE vulnerability in WinRAR with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-10520 | Ivanti Sentry | Critical | Actively exploited RCE vulnerability in Ivanti Sentry with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-11645 | Google Chromium V8 and Chrome | Critical | Actively exploited RCE vulnerability in Google Chromium V8/Chrome with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-12569 | PTC Windchill, Windchill PDMLink, and FlexPLM | Critical | Actively exploited vulnerability in PTC Windchill products with risk score 99; listed in CISA KEV. |
| CVE-2026-20230 | Cisco Unified Communications Manager | Critical | Actively exploited vulnerability in Cisco Unified Communications Manager with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager and Controller | Critical | Actively exploited RCE vulnerability in Cisco Catalyst SD-WAN Manager and Controller with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-20253 | Splunk Enterprise | Critical | Actively exploited vulnerability in Splunk Enterprise with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Critical | Actively exploited vulnerability in Cisco Catalyst SD-WAN Manager with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-21509 | Microsoft 365 Apps for Enterprise and Office 2016 | Critical | Actively exploited RCE vulnerability exploited by APT36 in operations targeting India; risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-28318 | SolarWinds Serv-U | Critical | Actively exploited vulnerability in SolarWinds Serv-U with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform | Critical | Actively exploited RCE vulnerability in Microsoft Defender Antimalware Platform with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-34908 | Ubiquiti UniFi OS, UniFi OS Server, UDM, and UDM-Pro | Critical | Actively exploited vulnerability in Ubiquiti UniFi OS products with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-34909 | Ubiquiti UniFi OS, UniFi OS Server, Express 7, and UDM | Critical | Actively exploited vulnerability in Ubiquiti UniFi OS products with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-34910 | Ubiquiti UniFi OS, UniFi OS Server, UDM, and UDM-Pro | Critical | Actively exploited RCE vulnerability in Ubiquiti UniFi OS products with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | Critical | Actively exploited vulnerability in Oracle PeopleSoft Enterprise PeopleTools with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-39808 | FortiSandbox PaaS | Critical | Actively exploited RCE vulnerability in FortiSandbox PaaS with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-41089 | Microsoft Windows Server 2012 | Critical | Actively exploited RCE vulnerability in Microsoft Windows Server 2012 with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-42271 | BerriAI LiteLLM | Critical | Actively exploited RCE vulnerability in BerriAI LiteLLM with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-48558 | SimpleHelp | Critical | Actively exploited vulnerability in SimpleHelp with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-48907 | Joomla Content Editor (JCE) extension for Joomla | Critical | Actively exploited vulnerability in Joomla JCE extension with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-50751 | Check Point Security Gateway, Quantum Security Gateway, and Spark Firewalls | Critical | Actively exploited vulnerability associated with Qilin Ransomware; risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-54420 | LiteSpeed cPanel Plugin | Critical | Actively exploited vulnerability in LiteSpeed cPanel Plugin with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2026-7473 | Arista EOS | Critical | Actively exploited vulnerability in Arista EOS with risk score 99; listed in CISA KEV with public PoC available. |
| CVE-2021-26855 | Microsoft Exchange Server 2016 and 2019 | High | Actively exploited RCE vulnerability (ProxyLogon component) used in StrikeShark campaign; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2021-36260 | Hikvision Firmware | High | Actively exploited RCE vulnerability in Hikvision firmware used in StrikeShark campaign; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2022-40684 | Fortinet FortiOS, FortiProxy, and FortiSwitchManager | High | Actively exploited authentication bypass vulnerability used in StrikeShark campaign; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2023-20198 | Cisco IOS XE Software | High | Actively exploited vulnerability in Cisco IOS XE Web UI used in StrikeShark campaign; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2024-21182 | Oracle WebLogic Server | High | Actively exploited vulnerability in Oracle WebLogic Server with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2024-21762 | Fortinet FortiProxy and FortiOS | High | Actively exploited RCE vulnerability in Fortinet FortiProxy/FortiOS used in StrikeShark campaign; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2025-48595 | Android Framework | High | Actively exploited RCE vulnerability in Android Framework with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2025-6218 | WinRAR | High | Actively exploited RCE vulnerability in WinRAR with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2026-21513 | Microsoft Windows 10 and Windows Server 2012 | High | Actively exploited vulnerability exploited by APT36 in operations targeting India; risk score 89; listed in CISA KEV. |
| CVE-2026-3300 | WPEverest Everest Forms Pro | High | Actively exploited RCE vulnerability in WPEverest Everest Forms Pro with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2026-35616 | Fortinet FortiClient EMS | High | Actively exploited RCE vulnerability in Fortinet FortiClient EMS linked to EKZ information-stealing malware delivery; Nuclei template created by Insikt Group; risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2026-41091 | Microsoft Malware Protection Engine | High | Actively exploited vulnerability in Microsoft Malware Protection Engine with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2026-44963 | Veeam Backup and Replication | High | Actively exploited vulnerability in Veeam Backup and Replication with risk score 89; listed in CISA KEV. |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer for Magento 2 | High | Actively exploited RCE vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 with risk score 89; listed in CISA KEV with public PoC available. |
| CVE-2016-4437 | Apache Shiro | Medium | Actively exploited RCE vulnerability in Apache Shiro used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2021-27076 | Microsoft SharePoint and Business Productivity Servers | Medium | Actively exploited vulnerability in Microsoft SharePoint used in StrikeShark campaign; risk score 79; listed in CISA KEV. |
| CVE-2021-27137 | DD-WRT Firmware | Medium | Actively exploited vulnerability in DD-WRT firmware linked to C0XMO botnet propagation across Linux architectures; risk score 79; listed in CISA KEV. |
| CVE-2022-27925 | Zimbra | Medium | Actively exploited vulnerability in Zimbra used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2022-41082 | Microsoft Exchange Server 2013 | Medium | Actively exploited RCE vulnerability (ProxyNotShell component) in Microsoft Exchange Server 2013 used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2023-32315 | Openfire | Medium | Actively exploited vulnerability in Openfire used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2023-46747 | F5 BIG-IP | Medium | Actively exploited RCE vulnerability in F5 BIG-IP used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2024-36401 | GeoServer | Medium | Actively exploited RCE vulnerability in GeoServer used in StrikeShark campaign; risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-25089 | Fortinet FortiSandbox PaaS and Cloud | Medium | Actively exploited RCE vulnerability in Fortinet FortiSandbox PaaS and Cloud with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-39813 | Fortinet FortiSandbox and Cloud | Medium | Actively exploited vulnerability in Fortinet FortiSandbox and Cloud with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-4020 | Gravity SMTP | Medium | Actively exploited vulnerability in Gravity SMTP with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-45586 | Microsoft Windows 10 and Windows Server 2012 | Medium | Actively exploited vulnerability in Microsoft Windows 10 and Windows Server 2012 with risk score 79; listed in CISA KEV. |
| CVE-2026-46817 | Oracle Payments | Medium | Actively exploited vulnerability in Oracle Payments with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-5027 | Langflow | Medium | Actively exploited vulnerability in Langflow with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-8206 | Kirki – Freeform Page Builder, Website Builder & Customizer | Medium | Actively exploited vulnerability in Kirki Page Builder with risk score 79; listed in CISA KEV with public PoC available. |
| CVE-2026-25939 | Frangoteam FUXA | Medium | Actively exploited vulnerability in Frangoteam FUXA with risk score 72; Nuclei template created by Insikt Group; listed in CISA KEV with public PoC available. |
Attack Chain
- Initial Access: Threat actors exploit externally reachable enterprise applications and appliances using known CVEs (e.g., FortiOS, Cisco IOS XE, Exchange Server, React Server Components)
- Execution: Exploited vulnerabilities deploy loaders such as SharkLoader or directly execute backdoor code on compromised hosts
- Persistence/C2: Loaders deliver second-stage payloads including Cobalt Strike beacons, COPPERHEDGE, EtherRAT, or SHEETCREEP backdoors establishing persistent command-and-control channels
- Lateral Movement: Attackers use compromised credentials and additional vulnerability exploitation to move laterally across the network via RCE-capable CVEs
- Exfiltration/Impact: Data exfiltration via established C2 channels; in ransomware cases (Qilin), data is encrypted and exfiltrated for double extortion
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: Yes
- Platforms: Nuclei templates (Recorded Future Intelligence Operations Platform)
Insikt Group created Nuclei templates for CVE-2026-35616 (Fortinet FortiClient EMS) and CVE-2026-25939 (Frangoteam FUXA), available to Recorded Future customers. No YARA, Sigma, Snort/Suricata, or SIEM queries are provided in the public article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect post-exploitation behaviors such as Cobalt Strike beaconing, backdoor processes, and suspicious child process relationships. However, exploitation of network appliances (FortiOS, Cisco IOS XE, Ubiquiti UniFi) and IoT firmware (DD-WRT, Hikvision) typically occurs on devices without EDR coverage. |
| Network Visibility | Medium | Network monitoring can detect C2 traffic and anomalous connections to public-facing applications. However, many exploits target legitimate management interfaces (web UIs, APIs) and may blend with normal administrative traffic. Encrypted C2 channels further reduce visibility. |
| Detection Difficulty | Moderate | 53 of 60 vulnerabilities have public PoC exploits, making signature-based detection feasible for known exploit attempts. However, the breadth of affected products (36 vendors), use of legitimate management interfaces, and lack of EDR on network appliances create significant blind spots. Supply chain compromise via dependency confusion (CVE-2025-55182) is particularly difficult to detect without package integrity monitoring. |
Required Log Sources
- Vulnerability scanner output with CVE mapping
- Firewall and reverse proxy logs for public-facing applications
- IDS/IPS alerts for known exploit signatures
- EDR telemetry for post-exploitation behavior (process creation, network connections)
- Web server access logs for anomalous requests targeting known CVEs
- Network appliance syslogs (FortiOS, Cisco IOS XE, UniFi OS)
- DNS resolution logs for C2 domain lookups
- Authentication logs for anomalous login patterns post-exploitation
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for processes spawned by web server or application service accounts that exhibit unexpected child process creation patterns, which may indicate successful exploitation of a public-facing application (T1190). | EDR process creation events with parent-child relationship analysis; web server access logs correlated with process execution | Initial Access / Execution | Medium — legitimate administrative scripts or application updates may spawn child processes from service accounts |
| Consider hunting for network connections from internal hosts to previously unknown external endpoints following anomalous inbound traffic to public-facing services, which may indicate C2 channel establishment post-exploitation. | NetFlow/PCAP data, firewall logs, DNS resolution logs, EDR network connection events | Command and Control | Medium — legitimate application updates or cloud service connections may generate similar patterns |
| Consider hunting for suspicious Python package installations or imports that reference packages with names similar to legitimate libraries, which may indicate dependency confusion attacks related to CVE-2025-55182 exploitation. | Package manager logs (pip, npm), EDR file creation events in Python site-packages directories, network connections to PyPI or npm registries | Initial Access / Execution | Low to Medium — typos in package names or internal package mirrors may generate false positives |
| Consider hunting for anomalous authentication events on network appliances (FortiOS, Cisco IOS XE, UniFi OS) following external connection attempts, which may indicate exploitation of authentication bypass or missing authentication CVEs. | Network appliance syslogs, authentication logs, firewall session logs for management interfaces | Initial Access / Persistence | Low — administrative access patterns are typically well-established and predictable |
| Consider hunting for rapid sequential exploitation attempts against multiple CVEs from the same source IP or subnet, which may indicate a coordinated campaign such as StrikeShark chaining multiple vulnerabilities. | IDS/IPS alerts, web application firewall logs, SIEM correlation across multiple CVE-based detection rules | Initial Access / Lateral Movement | Low — legitimate vulnerability scanners may trigger multiple detections but typically from known scanner IPs and during scheduled windows |
Control Gaps
- Network appliances and IoT devices (FortiOS, Cisco IOS XE, DD-WRT, Hikvision, Ubiquiti) typically lack EDR agents, creating blind spots for post-exploitation detection
- Supply chain attacks via dependency confusion (CVE-2025-55182) may bypass traditional perimeter controls and application allowlisting
- Exploitation of legitimate management interfaces on public-facing appliances may not trigger IDS signatures if the exploit blends with normal administrative traffic
- Public PoC availability for 53 of 60 vulnerabilities lowers the barrier for exploitation but also increases noise from scanning activity, potentially masking targeted attacks
- Legacy vulnerabilities (4 of 60 are 5+ years old) may not be covered by current detection rules if they were assumed to be remediated
Key Behavioral Indicators
- Unexpected child processes spawned by web server or application service accounts (e.g., IIS w3wp.exe spawning cmd.exe or powershell.exe)
- Inbound HTTP requests matching known CVE exploit patterns targeting specific endpoints or parameters on public-facing applications
- Anomalous outbound network connections from servers or appliances following inbound exploitation attempts
- Python package installations with names closely resembling legitimate packages (dependency confusion indicators)
- Rapid sequential exploitation attempts against multiple CVEs from a single source, suggesting coordinated campaign activity
- Authentication events on network appliances from unexpected source IPs or without corresponding management session establishment
- Cobalt Strike beacon patterns in network traffic following successful exploitation of public-facing applications
False Positive Assessment
Medium — Many of the 53 public PoC exploits may be used by legitimate vulnerability scanners and security researchers, generating noise that can mask targeted exploitation. Exploitation of management interfaces on network appliances may blend with legitimate administrative activity. Dependency confusion detection may trigger on legitimate package updates with similar names. However, correlation of multiple CVE exploitation attempts from a single source (campaign behavior) has lower false positive risk.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider prioritizing patching for all 23 CVEs listed in CISA's KEV catalog, as these have confirmed active exploitation.
- If applicable to your environment, consider immediately patching CVE-2025-55182 (React Server Components/Next.js) given its CVSS 10.0 score, Lazarus Group exploitation, and use in deploying COPPERHEDGE and EtherRAT.
- Consider reviewing internet-facing assets for exposure to the 57 actively exploited CVEs listed in the article, prioritizing those with risk scores of 99 and public PoC availability.
- If your organization uses Fortinet FortiClient EMS (CVE-2026-35616) or Frangoteam FUXA (CVE-2026-25939), consider applying the Nuclei templates provided by Insikt Group to identify vulnerable instances, if you have access to the Recorded Future platform.
- Consider blocking or restricting access to public-facing management interfaces for network appliances (FortiOS, Cisco IOS XE, UniFi OS) where remote exploitation CVEs have been identified, if supported by your network architecture.
Infrastructure Hardening
- Consider implementing network segmentation to isolate network appliances and IoT devices from general corporate networks, limiting lateral movement opportunities post-exploitation.
- Evaluate whether your web application firewall rules cover exploit patterns for the 53 CVEs with public PoC exploits, particularly those targeting CWE-22 (Path Traversal) and CWE-78 (OS Command Injection).
- Consider implementing package integrity verification and allowlisting for Python and npm dependencies to mitigate dependency confusion attacks related to CVE-2025-55182.
- If your organization uses any of the 36 affected vendor products, consider establishing a vulnerability management cadence that prioritizes based on exploitation likelihood (KEV listing, PoC availability) rather than CVSS score alone.
- Consider deploying additional monitoring (syslog forwarding, NetFlow collection) on network appliances that lack EDR coverage to improve detection of post-exploitation activity.
User Protection
- Consider ensuring endpoint protection is updated on all systems running Microsoft Defender Antimalware Platform and Malware Protection Engine, given CVE-2026-33825 and CVE-2026-41091 which target security products themselves.
- If your organization uses Microsoft 365 Apps or Office 2016, consider applying patches for CVE-2026-21509, which APT36 has actively exploited in targeted operations.
- Consider updating WinRAR installations promptly, as two separate WinRAR CVEs (CVE-2025-8088 and CVE-2025-6218) were actively exploited this month with public PoCs available.
- Evaluate whether your email security gateway can detect and block documents exploiting Microsoft Office vulnerabilities (CVE-2026-21509) used by APT36 in targeted phishing operations.
Security Awareness
- Consider incorporating awareness of supply chain attacks (dependency confusion) into developer training programs, particularly for teams using React/Next.js and Python package ecosystems.
- Consider reminding IT and network operations teams about the risk of leaving management interfaces exposed to the internet, given the prevalence of appliance exploitation in this month's CVE landscape.
- Consider rolling into existing awareness programs guidance on verifying the legitimacy of Python and npm packages before installation, given the dependency confusion vector used in CVE-2025-55182 exploitation.
- If applicable to your organization, consider briefing stakeholders on the elevated risk from the 49% month-over-month increase in high-impact vulnerabilities and the need for accelerated patching cycles.