Executive Summary
In June 2026, Insikt Group identified 60 high-impact vulnerabilities, marking a 49% increase from the previous month. Notably, 23 of these vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)'s Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities affected products from 36 vendors, with Microsoft accounting for approximately 18%. (vulnerability-lookup.org)
This surge underscores the escalating threat landscape, emphasizing the need for organizations to prioritize vulnerability management and remediation efforts to mitigate potential exploits.
Why This Matters Now
The significant rise in high-impact vulnerabilities highlights the urgent need for organizations to enhance their cybersecurity posture and promptly address identified weaknesses to prevent potential breaches.
Attack Path Analysis
The attack began with the exploitation of CVE-2025-55182 (React2Shell) in React Server Components, allowing unauthenticated remote code execution. The attackers then escalated privileges by deploying backdoors such as HISONIC and COMPOOD, gaining deeper access to the compromised systems. Subsequently, they moved laterally across the network, targeting additional systems and services. For command and control, the attackers established persistent communication channels to exfiltrate data and receive further instructions. They exfiltrated sensitive data from the compromised systems. Finally, the attackers deployed cryptocurrency miners like XMRIG, impacting system performance and resource availability.
Kill Chain Progression
Initial Compromise
Description
Exploitation of CVE-2025-55182 (React2Shell) in React Server Components allowed unauthenticated remote code execution.
Related CVEs
CVE-2026-35616
CVSS 9.8An improper access control vulnerability in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute unauthorized code or commands via crafted requests.
Affected Products:
Fortinet FortiClientEMS – 7.4.5, 7.4.6
Exploit Status:
exploited in the wildCVE-2026-25939
CVSS 9.1An authorization bypass vulnerability in Frangoteam FUXA versions 1.2.8 through 1.2.10 allows unauthenticated, remote attackers to create and modify arbitrary schedulers, potentially impacting connected ICS/SCADA environments.
Affected Products:
Frangoteam FUXA – 1.2.8, 1.2.9, 1.2.10
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Exploitation of Remote Services
Exploitation for Privilege Escalation
Exploitation for Defense Evasion
Exploitation for Credential Access
Exploitation for Defense Impairment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System and Application Security
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Multi-campaign exploitation targeting IT infrastructure through enterprise applications, network devices, and cloud platforms requires enhanced zero-trust segmentation and encrypted traffic monitoring.
Financial Services
Lazarus Group's CVE-2025-55182 exploitation targeting financial organizations via React Server Components demands immediate egress security and anomaly detection implementation for regulatory compliance.
Telecommunications
Network infrastructure vulnerabilities in Cisco, Fortinet, and Ubiquiti systems enable lateral movement and command control, necessitating east-west traffic security and multicloud visibility controls.
Government Administration
APT36 targeting India through Microsoft vulnerabilities and CISA KEV catalog inclusion requires enhanced threat detection, policy enforcement, and secure hybrid connectivity implementations.
Sources
- June 2026 CVE Landscapehttps://www.recordedfuture.com/blog/june-2026-cve-landscapeVerified
- FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/Verified
- AL26-007 - Vulnerability impacting Fortinet FortiClientEMS - CVE-2026-35616https://www.cyber.gc.ca/en/alerts-advisories/al26-007-vulnerability-impacting-fortinet-forticlientems-cve-2026-35616Verified
- CVE-2026-25939: Frangoteam FUXA Auth Bypass Vulnerabilityhttps://www.sentinelone.com/vulnerability-database/cve-2026-25939/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation may occur, Aviatrix CNSF would likely limit the attacker's ability to move beyond the compromised workload.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies.
Aviatrix CNSF would likely limit the attacker's ability to deploy and operate unauthorized software by enforcing strict workload segmentation and monitoring.
Impact at a Glance
Affected Business Functions
- Endpoint Security Management
- Industrial Control Systems Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Potential unauthorized access to sensitive operational technology configurations and endpoint security policies.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of attacks.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Ensure regular patching and updating of software to mitigate known vulnerabilities like CVE-2025-55182.



