CVE Tools

One Box, Three Perfect 10s: The Week Networking Gear Broke Bad

Ubiquiti UniFi OS, Lantronix, Splunk, Cisco and a resurfacing Fortinet bug — what's actually exploited this week

It's rare to see one product collect three perfect-10s in a single week. This week Ubiquiti's UniFi OS managed exactly that — CVE-2026-34910, CVE-2026-34908 and CVE-2026-34909, all CVSS 10, all added to CISA's KEV in the same June 23 batch, with the federal remediation deadline set for June 26.

CVSS 10 is the loud part. The part that should make you sit up is on KEV — that's CISA saying these are being used in real attacks, not just theoretically nasty. The command-injection one (CVE-2026-34910) carries an EPSS of 82% (99th percentile, as of June 25); the access-control and path-traversal siblings score lower on likelihood but ride the same KEV entry. BleepingComputer and SecurityWeek both have the write-ups.

On the agenda

Same June 23 KEV batch, different box: CVE-2025-67038 in Lantronix EDS5000 serial-to-Ethernet gateways — a 9.8 command injection where the login username gets stitched straight into a shell command. Its EPSS is a sleepy 1.1%, which is exactly why likelihood scores can mislead: it's already exploited and confirmed by CISA. KEV beats EPSS here.

CVE-2026-20253, the Splunk Enterprise pre-auth file-write we flagged a fortnight ago, is still live — 9.8, on KEV, EPSS 92%, and its federal deadline (June 21) is already in the rear-view mirror. Fix is Splunk Enterprise 10.2.4 / 10.0.7. BleepingComputer covered the "patch by Sunday" warning.

Flying under the radar

Remember the Cisco SD-WAN bug from a few weeks back? Here's another to file next to it. CVE-2026-20262 in Cisco Catalyst SD-WAN Manager is "only" a 6.5 — but it's on KEV, in the wild, and now has a public exploit. A modest CVSS that's actually being used outranks a quiet 9.8 every time. (Check Point's weekly intel has it.)

And the old guard never quite dies: CVE-2024-21762, the 2024 Fortinet FortiOS/FortiProxy SSL-VPN out-of-bounds write (9.8, ransomware-linked on KEV), resurfaced this week inside the StrikeShark Cobalt Strike campaign. Its federal deadline passed in February 2024 — but attackers clearly didn't get the memo.

CVEProduct → fixStatus
CVE-2026-34910 / -34908 / -34909Ubiquiti UniFi OS → vendor updateCVSS 10, on KEV (deadline Jun 26)
CVE-2026-20253Splunk Enterprise → 10.2.4 / 10.0.79.8, on KEV, exploited
CVE-2026-20262Cisco Catalyst SD-WAN Manager → vendor patch6.5, on KEV, public exploit
CVE-2025-67038Lantronix EDS5000 → vendor update9.8, on KEV, exploited
CVE-2024-21762Fortinet FortiOS / FortiProxy → fixed builds9.8, on KEV, ransomware

UniFi gateways, Lantronix gateways, Fortinet VPNs, Cisco managers, Splunk consoles — this is perimeter gear, the stuff that lives at the edge of your network and the stuff teams most often forget they have online. You watch the threat feed all week. The harder question is which of these boxes you're quietly exposing right now.

Are the Ubiquiti UniFi OS bugs (CVE-2026-34910 / -34908 / -34909) being exploited?
Yes. All three are CVSS 10 and were added to CISA's KEV on June 23, 2026 — meaning CISA has evidence of real-world exploitation. The federal remediation deadline is June 26. Update UniFi OS per Ubiquiti's instructions. Free single-CVE check.
How do I fix CVE-2026-20253 in Splunk Enterprise?
Upgrade to Splunk Enterprise 10.2.4 (10.2.x) or 10.0.7 (10.x). It's a 9.8 pre-auth file-write, on KEV and actively exploited, with the federal deadline already passed — treat it as urgent.
Why is a 6.5 (CVE-2026-20262, Cisco) on this list above 9.8 bugs?
Because severity (CVSS) isn't risk. CVE-2026-20262 is on KEV, exploited in the wild, and now has a public exploit. An exploited 6.5 is more urgent than a 9.8 nobody is touching — that's the SSVC way of prioritising.
Is the old Fortinet bug CVE-2024-21762 still a threat in 2026?
Yes. The 2024 FortiOS/FortiProxy SSL-VPN flaw (9.8, ransomware-linked on KEV) resurfaced this week in a fresh Cobalt Strike campaign. Old vulnerabilities keep working on unpatched, internet-facing boxes. Patch to fixed FortiOS/FortiProxy builds.
How do I know if any of these are exposed on my own network?
Most of this week's bugs are in internet-facing perimeter gear (UniFi, Lantronix, Fortinet, Cisco, Splunk). A free External Exposure Review maps what's reachable from the outside — exposed services, forgotten systems and leaked credentials — in a few minutes.