VORANT. Threat Intelligence Sign in Get the full feed

CISA adds Lantronix, Ubiquiti flaws to KEV

high vulnerability

CISA added four actively exploited vulnerabilities affecting Lantronix EDS5000 and Ubiquiti UniFi OS devices to its Known Exploited Vulnerabilities Catalog.

CISA has updated its Known Exploited Vulnerabilities Catalog with four new entries based on evidence of active exploitation in the wild. The additions include CVE-2025-67038, a code injection vulnerability in Lantronix EDS5000 devices, and three flaws in Ubiquiti UniFi OS: CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), and CVE-2026-34910 (improper input validation).

The KEV Catalog supports CISA's Binding Operational Directive 26-04, which mandates Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could grant total control post-exploitation. While the directive applies only to federal agencies, CISA recommends all organizations adopt risk-based vulnerability management practices and prioritize patching KEV-listed vulnerabilities.

Organizations using affected Lantronix or Ubiquiti products should apply available patches immediately and assess whether systems were compromised prior to remediation. CISA continues to accept nominations for additional KEV entries through its online submission form.

Mentioned in this report

Vulnerabilities CVE-2025-67038KEVCVE-2026-34908KEVCVE-2026-34909KEVCVE-2026-34910KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free