Weekly Threat Brief: Edge, AI, and Control Planes Under Attack

Published: June 15, 2026

Week Ending: June 14, 2026 | Overall Risk Posture: Critical

The week ending June 14 was not defined by one single vulnerability class. It was defined by exploitation pressure against systems that sit close to access, routing, AI services, browsers, mobile gateways, and enterprise business workflows.

CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalog this week. The additions affected BerriAI LiteLLM, Check Point Security Gateway, Cisco Catalyst SD-WAN, Google Chromium V8, Arista EOS, Ivanti Sentry, and Oracle PeopleSoft Enterprise PeopleTools.

The affected technologies sit in very different places: AI gateway infrastructure, remote access VPN, SD-WAN control systems, browser engines, switching platforms, mobile access gateways, and major enterprise applications. But they share one common lesson. Attackers are not only looking for vulnerable endpoints. They are targeting the trusted systems that connect users, applications, networks, and business processes.

Threat at a Glance

Threat Area Key Issue Why It Matters Defender Priority
AI Infrastructure BerriAI LiteLLM was added to KEV for CVE-2026-42271. AI gateways can hold model provider keys, internal API routes, prompts, logs, and access to downstream services. Update LiteLLM, restrict proxy/admin access, review MCP exposure, and rotate secrets if compromise is suspected.
Remote Access VPN Check Point Security Gateway was added for CVE-2026-50751. An authentication bypass in VPN infrastructure can turn the perimeter itself into the entry point. Apply vendor hotfixes, remove deprecated IKEv1 exposure where possible, and review VPN session activity.
SD-WAN Infrastructure Cisco Catalyst SD-WAN was added for CVE-2026-20245. SD-WAN systems influence routing, site connectivity, traffic policy, and management-plane behavior. Apply Cisco guidance, restrict management access, and review administrative and control-plane logs.
Browsers Google Chromium V8 was added for CVE-2026-11645. Browser flaws are high-value because browsers sit directly in the path of web content, SaaS sessions, and identity workflows. Force Chrome and Chromium-based browser updates, confirm relaunch, and prioritize privileged users.
Network Switching Arista EOS was added for CVE-2026-7473. Unexpected tunnel decapsulation can weaken segmentation assumptions and traffic-handling expectations. Review affected tunnel configurations, apply mitigations, and validate network segmentation behavior.
Mobile Gateway Infrastructure Ivanti Sentry was added for CVE-2026-10520. Unauthenticated root-level remote code execution on a gateway product creates immediate perimeter risk. Upgrade affected versions urgently and investigate exposed appliances for signs of compromise.
Enterprise Applications Oracle PeopleSoft Enterprise PeopleTools was added for CVE-2026-35273. PeopleSoft often supports HR, payroll, finance, student administration, and other sensitive business processes. Apply Oracle guidance, restrict exposure, and review authentication, access, and administrative activity.

Active Exploitation and Immediate Risk

  • LiteLLM showed that AI infrastructure is now part of the active exploitation cycle
    On June 8, CISA added CVE-2026-42271, a LiteLLM command-execution vulnerability involving MCP stdio transport that has been observed in active exploitation.

    LiteLLM is often used as an AI gateway or proxy layer between internal applications and external model providers. That makes it more sensitive than a simple developer tool. In production environments, an AI proxy may handle provider API keys, model-routing rules, logs, prompt content, environment variables, and connections to downstream systems.

    The vulnerability is important because it shows how AI middleware can become operational infrastructure before security ownership is mature. Features built for testing, routing, model access, or integration can become execution paths when access control and input handling are not tight enough.

    Defenders should identify where LiteLLM is deployed, especially in internal AI tools, Kubernetes environments, developer platforms, or experimental services that quietly became production dependencies. The response should include updating the software, restricting access to proxy and administrative functions, reviewing MCP-related exposure, and rotating secrets if compromise is suspected.
  • Check Point VPN exploitation reinforced the danger of edge authentication flaws
    On June 8, CISA also added CVE-2026-50751, affecting Check Point Security Gateway remote access and mobile access deployments using deprecated IKEv1 VPN paths.

    The issue involves improper authentication logic in certificate validation. In affected configurations, an attacker may be able to establish a VPN session without possessing a valid user password.

    The practical risk is direct. A VPN gateway is not just another internet-facing server. It is a trusted access path into the enterprise. If authentication can be bypassed, attackers may not need phishing, malware delivery, or endpoint compromise as the first step. The remote access system itself becomes the door.

    Defenders should prioritize exposed Check Point gateways, especially where Remote Access VPN, Mobile Access, or Spark Firewall deployments still support deprecated IKEv1 behavior. The response should include applying vendor hotfixes, removing deprecated protocol exposure where possible, and reviewing VPN logs for unusual source geographies, abnormal session timing, unexpected users, and access to sensitive internal systems.
  • Cisco Catalyst SD-WAN kept control-plane risk in focus
    On June 9, CISA added CVE-2026-20245, affecting Cisco Catalyst SD-WAN.

    The vulnerability involves privilege escalation on SD-WAN infrastructure. While exploitation requires access to the affected environment, the platform role makes the issue more important. SD-WAN systems help manage traffic policy, site connectivity, routing, and distributed network control.

    A vulnerability on this kind of system should not be treated like an ordinary server bug. If an attacker gains a foothold on a control-plane component, privilege escalation can increase access to routing, configuration, management interfaces, and network-wide visibility.

    Defenders should apply Cisco guidance, restrict management access, review local administrative accounts, and inspect control-plane logs for suspicious configuration changes, unexpected command activity, or abnormal administrative sessions. SD-WAN infrastructure should be handled as high-value management infrastructure, not background networking equipment.
  • Google Chromium V8 showed why browser patching is still an emergency workflow
    On June 9, CISA added CVE-2026-11645, a Google Chromium V8 out-of-bounds read and write vulnerability.

    Google confirmed that exploitation existed in the wild. Browser vulnerabilities remain high-value because browsers sit directly in the path of modern work: email links, SaaS applications, identity portals, cloud consoles, internal dashboards, and administrative tools.

    A browser bug on an ordinary workstation is serious. A browser bug on a privileged workstation can be more serious. Administrators, developers, finance users, executives, help desk staff, and security teams often maintain access to sensitive SaaS, cloud, identity, and internal systems through long-lived browser sessions.

    Defenders should confirm that Chrome has moved to a fixed version and that users have relaunched the browser. Managed update status alone is not enough if the vulnerable browser process is still running. Teams should also verify other Chromium-based browsers where their vendors have shipped corresponding updates.
  • Arista EOS brought tunnel and forwarding behavior into the KEV picture
    On June 9, CISA added CVE-2026-7473, affecting Arista Extensible Operating System.

    The issue involves tunnel decapsulation behavior. Under affected conditions, a switch configured as a tunnel endpoint may incorrectly process unexpected tunneled traffic when certain configurations are present, such as VXLAN VTEP, GRE tunnel endpoint, or IP decapsulation groups.

    This is not a typical remote-code-execution story, but it still matters. Network devices enforce assumptions. Segmentation, overlay networking, routing, and inspection paths depend on traffic being processed exactly as intended. If tunneled traffic is forwarded unexpectedly, defenders may have a segmentation problem they cannot see from endpoint telemetry alone.

    Security teams should work with network teams to identify affected EOS deployments, review tunnel endpoint configurations, validate decapsulation behavior, and apply Arista’s recommended mitigations. The priority is not only patching. It is confirming whether the network still behaves the way the architecture assumes.
  • Ivanti Sentry created another urgent perimeter-appliance moment
    On June 11, CISA added CVE-2026-10520, an Ivanti Sentry OS command injection vulnerability.

    The issue allows a remote unauthenticated attacker to achieve root-level remote code execution on affected Ivanti Sentry versions. That combination makes this one of the most urgent entries of the week: remote access, no authentication requirement, command injection, root-level impact, and active exploitation.

    Ivanti Sentry is a secure mobile gateway product. In many environments, gateway products are positioned near sensitive access paths. They may connect mobile devices to enterprise resources, sit close to authentication workflows, and operate near the boundary between external devices and internal systems.

    Defenders should upgrade affected versions urgently, but they should not stop there. Exposed appliances should be reviewed for compromise indicators, unusual processes, unexpected configuration changes, new or modified files, abnormal outbound connections, and suspicious administrative activity. If exploitation is suspected, integrated credentials and downstream trust relationships should be reviewed.
  • Oracle PeopleSoft reminded defenders that business platforms are high-value targets
    On June 12, CISA added CVE-2026-35273, affecting Oracle PeopleSoft Enterprise PeopleTools.

    Oracle described the issue as remotely exploitable without authentication. The vulnerability affects PeopleSoft Enterprise PeopleTools and can allow compromise of the platform over HTTP in affected versions.

    PeopleSoft is not just another enterprise application. It often supports sensitive workflows such as HR, payroll, finance, procurement, student administration, employee records, benefits, workforce operations, and business reporting. That makes exploitation risk different from a normal application vulnerability.

    Defenders should treat this as a business-critical remediation item. The response should include applying Oracle’s security alert guidance, reviewing internet exposure, checking HTTP access logs, reviewing administrative activity, validating integration accounts, and coordinating with the business teams that own the application.

Common Failure Patterns

  • AI infrastructure is moving faster than security ownership
    LiteLLM shows that AI gateways and model proxies are no longer theoretical security concerns. They may hold provider keys, prompts, logs, routing rules, and internal service connections, but many organizations still lack clear ownership for patching and monitoring these systems.
  • Deprecated functionality still creates modern incidents
    Check Point’s IKEv1-related exposure shows why legacy protocols and compatibility features should not be treated as harmless technical debt. Old access paths can remain reachable long after teams stop actively reviewing them.
  • Control-plane risk is still under-measured
    Cisco SD-WAN and Arista EOS highlight a common blind spot. Network infrastructure flaws may not always look like ordinary endpoint compromise, but they can affect routing, segmentation, forwarding, and management-plane trust.
  • Browser patching is only complete after relaunch
    Chrome may update quickly, but vulnerable browser processes can remain open. Managed update dashboards can give a false sense of completion if they do not confirm the running version after restart.
  • Enterprise applications often sit outside urgent security workflows
    PeopleSoft may be owned by business application teams rather than infrastructure teams. That separation can slow response when exploitation is confirmed, especially for systems tied to HR, payroll, finance, or student records.
  • Gateway appliances require both patching and investigation
    Ivanti Sentry and Check Point show that exposed gateway products should be treated as possible incident-risk assets once exploitation is confirmed. Patching is necessary, but evidence of prior compromise should also be reviewed.

Defender Priorities

  • Find and update LiteLLM deployments affected by CVE-2026-42271
    Identify where LiteLLM is running, especially in developer environments, AI pilots, Kubernetes clusters, internal tools, and model proxy services. Restrict access to administrative and proxy functions, review MCP-related exposure, and rotate API keys or environment secrets if compromise is suspected.
  • Patch Check Point Security Gateway and reduce legacy VPN exposure
    Apply Check Point hotfixes for CVE-2026-50751. Review whether Remote Access VPN, Mobile Access, or Spark Firewall configurations still rely on deprecated IKEv1 paths. Where possible, remove deprecated protocol exposure entirely.
  • Review VPN logs for suspicious access
    Look for unusual source geographies, abnormal login times, unexpected certificate behavior, unknown users, unusually long sessions, or access to sensitive internal resources shortly after VPN connection. Treat suspicious VPN access as a possible initial access event.
  • Apply Cisco Catalyst SD-WAN guidance and restrict management access
    Review local accounts, administrative roles, uploaded files, CLI activity, and configuration changes. SD-WAN management interfaces should be limited to trusted networks and monitored as high-value infrastructure.
  • Force Chrome and Chromium-based browser updates
    Confirm that Chrome has moved to a fixed version and that the browser has relaunched. Prioritize administrators, executives, developers, finance users, help desk users, cloud engineers, and security teams. Check other Chromium-based browsers separately.
  • Validate Arista EOS tunnel configurations
    Identify devices configured as tunnel endpoints, including VXLAN VTEPs, GRE tunnel endpoints, or IP decapsulation groups. Apply Arista mitigations and confirm that tunneled traffic cannot cross boundaries in unexpected ways.
  • Treat Ivanti Sentry as an urgent compromise-risk item
    Upgrade affected Ivanti Sentry versions immediately. Review exposed appliances for unusual processes, new files, modified configuration, abnormal outbound connections, unexpected users, or other evidence of compromise.
  • Escalate Oracle PeopleSoft remediation with business owners
    Apply Oracle guidance for CVE-2026-35273. Review PeopleTools versions, HTTP exposure, authentication logs, administrative activity, integration accounts, and unusual web requests. Coordinate with HR, finance, payroll, procurement, or student-system owners where applicable.
  • Use KEV as an exposure trigger, not just a patch list
    For each addition, ask four questions: is it internet-facing, does it control access, does it hold credentials, and does it support a sensitive business process? If any answer is yes, remediation should move ahead of ordinary backlog work.

Signals to Watch

  • AI gateways are becoming part of the enterprise attack surface
    LiteLLM’s KEV addition is a warning sign. AI proxies and gateways are starting to look like production middleware, with credentials, logs, routing logic, provider access, and internal service connections.
  • Remote access infrastructure remains a high-value target
    Check Point shows that VPN systems remain one of the most important assets to patch quickly. If the remote access layer fails, attackers may bypass many downstream controls.
  • Control planes are still under pressure
    Cisco SD-WAN and Arista EOS show that attackers and researchers continue to focus on infrastructure that shapes traffic, segmentation, forwarding, and enterprise connectivity.
  • Browser exploitation continues to create fleet-wide exposure
    Chromium V8 vulnerabilities matter because browsers are used for nearly every modern business workflow. Browser update compliance should be measurable, enforced, and verified after relaunch.
  • Mobile gateway appliances need stronger incident review
    Ivanti Sentry shows why gateway appliances should not be treated as “patch and forget” systems. If a root-level unauthenticated RCE is exploited, defenders should investigate the appliance, not only update it.
  • Business applications can become strategic compromise points
    PeopleSoft matters because it sits close to sensitive records and critical workflows. A business application compromise can quickly become a data, identity, finance, HR, or operations incident.

Weekly Pulse

The week ending June 14 showed exploitation pressure across several high-value enterprise layers: AI gateways, VPN infrastructure, SD-WAN systems, browsers, network switching, mobile gateways, and business applications.

LiteLLM represented AI gateway risk. Check Point represented remote access risk. Cisco Catalyst SD-WAN and Arista EOS represented control-plane and segmentation risk. Chrome represented browser-driven compromise. Ivanti Sentry represented mobile gateway exposure. Oracle PeopleSoft represented business application compromise.

The common thread is ownership. These systems often sit between teams, but attackers do not wait for internal responsibility to be clarified. Once CISA adds them to KEV, uncertainty itself becomes part of the risk.

Bottom Line

This week’s CISA KEV changes were not dominated by one vendor or one technology class. They showed exploitation across AI infrastructure, VPN gateways, SD-WAN systems, browser engines, switching platforms, mobile gateways, and enterprise applications.

For defenders, the priority is clear: update LiteLLM, patch Check Point Security Gateway, apply Cisco SD-WAN guidance, force Chrome and Chromium updates, review Arista EOS tunnel configurations, upgrade Ivanti Sentry, and remediate Oracle PeopleSoft PeopleTools.

The larger lesson is that KEV should be treated as an exploitation signal, not just a patch checklist. When a vulnerable system controls access, routes traffic, brokers AI requests, connects mobile users, or runs sensitive business workflows, remediation should move ahead of ordinary backlog work.

The risk is not only what is vulnerable. The risk is what the vulnerable system is trusted to do.

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.