June 2026: Urgent Focus on Rising Cyber Vulnerabilities

Jul 10, 2026 893 views

June 2026 saw a sharp uptick in serious cybersecurity vulnerabilities, with Insikt Group® identifying a total of 59 critical issues deserving immediate remediation attention. Among these, 30 vulnerabilities received a Very Critical Recorded Future Risk Score. This spike represents an alarming 47% increase from the previous month, underscoring a growing urgency within the sector.

Of the 59 vulnerabilities, 23 were featured in the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, while 33 vulnerabilities were reported directly by vendors. Interestingly, three vulnerabilities surfaced through honeypot data, indicating a variety of detection methods in play.

Product Vulnerability Overview

This month’s report highlights that these vulnerabilities span products from 36 different vendors, with Microsoft representing about 17% of the reported issues. The remaining vulnerabilities affect a diverse array of enterprise software, security solutions, network infrastructure, and cloud platforms. This broad distribution is a reminder that cyber defenses must be holistic and adaptable.

To aid in addressing two critical vulnerabilities from this month's report, Insikt Group has developed Nuclei templates for CVE-2026-35616 (affecting Fortinet FortiClient EMS) and CVE-2026-25939 (concerning Frangoteam FUXA). These detection tools are made available exclusively to Recorded Future customers via the Recorded Future Intelligence Operations Platform.

Active Exploits and Vulnerability Table

The following table lists all 59 vulnerabilities actively exploited within June 2026. Note that three CVEs from honeypot sources are excluded from this table; details for these can be accessed via the CVE Monthly report available to Recorded Future customers. The table also includes examples of public proof-of-concepts (PoCs) that were identified, though users should exercise caution and verify their validity before testing.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
Malware Analysis
RCE
PoC
1
CVE-2020-17103
99
Microsoft Windows 10/11 and Windows Server 2019
2
CVE-2022-0492
99
Linux Kernel
3
CVE-2025-55182
99
Meta React Server Components packages
4
CVE-2025-67038
99
Lantronix EDS5000
5
CVE-2025-8088
99
WinRAR
56
CVE-2026-25939
72
Frangoteam FUXA

Table 1: Summary of vulnerabilities actively exploited in June 2026 as reported by Recorded Future data.

Emerging Threats and Patterns

  • Key threats during June highlighted the exploitation of publicly accessible applications to deploy malware. Notably, StrikeShark abused several vulnerabilities, including CVE-2025-55182, prompting the deployment of SharkLoader alongside Cobalt Strike.
  • Remote code execution vulnerabilities accounted for 25 of the 59 vulnerabilities, implicating products from 18 different vendors, including mainstream names like Cisco, Fortinet, and Microsoft.
  • This month, Insikt Group noted the presence of public PoC exploits for 53 of the 59 vulnerabilities, demonstrating the readiness of attack vectors.
  • CWE-22 (Path Traversal) emerged as the most frequent flaw, closely followed by issues like CWE-502 (Deserialization of Untrusted Data) and CWE-78 (OS Command Injection), emphasizing the need for focused remediation strategies.
  • What’s particularly concerning is that four vulnerabilities from June’s report are at least five years old, demonstrating a grave trend where long-known weaknesses remain exploitable, primarily in environments that lag in applying patches. Moreover, the average time from a vulnerability’s public disclosure to active exploitation was strikingly brief at fewer than 24 hours.

Malware Trends Linked to Vulnerabilities

The June analysis revealed a strong correlation between malware campaigns and the exploitation of externally accessible enterprise applications. Insight from Insikt Group indicated that multiple vulnerabilities led to widespread attacks, with specific campaigns linked to notorious groups like Lazarus and StrikeShark. Using CVE-2025-55182, Lazarus deployed COPPERHEDGE targeting financial institutions, while APT36 focused on Microsoft vulnerabilities in operations within India.

Furthermore, the C0XMO botnet's activity was rooted in vulnerabilities associated with DD-WRT routers, showcasing a growing nexus between malware deployment and outdated software. Registration of Qilin ransomware tied to vulnerabilities impacting Check Point security gateways underlines the urgency of vulnerability management as a central focus for IT security teams.

For those monitoring this dynamic threat landscape, insights into PoC exploit trends are readily available to Recorded Future clients, reinforcing the importance of proactive vulnerability management across the board.

Source: William Williams · www.recordedfuture.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

June 2026 CVE Landscape