Date: 2026/06/09

【Vulnerability Alert】CISA Adds 5 Known Exploited Vulnerabilities to KEV Catalog (2026/06/01-2026/06/07)

  • Subject: 【Vulnerability Alert】CISA Adds 5 Known Exploited Vulnerabilities to KEV Catalog (2026/06/01-2026/06/07)


  • Description:
    • Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202606-00000005
    • 【CVE-2024-21182】Oracle WebLogic Server Unspecified Vulnerability (CVSS v3.1: 7.5)
    • 【Known Ransomware Campaign Use: Unknown】 Oracle WebLogic contains an unspecified vulnerability. An unauthenticated attacker connecting via T3 or IIOP protocols could exploit this vulnerability to compromise Oracle WebLogic Server. Successful exploitation could lead to unauthorized access to critical data or grant the attacker complete access to all data accessible by Oracle WebLogic Server.
    • 【CVE-2022-0492】Linux Kernel Improper Authentication Vulnerability (CVSS v3.1: 7.8)
    • 【Known Ransomware Campaign Use: Unknown】 Linux Kernel contains an improper authentication vulnerability where an attacker could achieve privilege escalation through the release_agent feature of cgroups v1.
    • 【CVE-2025-48595】Android Framework Integer Overflow Vulnerability (CVSS v3.1: 8.4)
    • 【Known Ransomware Campaign Use: Unknown】 Android Framework contains an integer overflow vulnerability that could lead to arbitrary code execution, resulting in local privilege escalation.
    • 【CVE-2026-45247】Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)

Computer and Communication Center
Network Systems Division