EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 11, 20263 min read

Security Briefing | June 11, 2026 - Langflow RCE Exploited, CISA Issues 3-Day Patch Directive, China Botnet Hits 1,500 Devices

Multiple critical vulnerabilities are under active exploitation, including an unpatched Langflow flaw (CVE-2026-5027) and a max-severity Ivanti Sentry bug. CISA has added three new flaws to its KEV catalog and issued a new directive requiring agencies to patch critical exploited vulnerabilities within three days. China-linked JDY botnet has expanded to over 1,500 devices targeting U.S. military networks, while OceanLotus continues espionage campaigns against Vietnamese entities.

By EACA Summit Content Team

Security Briefing | June 11, 2026 - Langflow RCE Exploited, CISA Issues 3-Day Patch Directive, China Botnet Hits 1,500 Devices

1. Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

A high-severity path traversal vulnerability (CVE-2026-5027, CVSS 8.8) in the open-source AI development platform Langflow is being actively exploited in the wild. The flaw allows unauthenticated attackers to write arbitrary files to the system, leading to remote code execution. Multiple sources confirm exploitation, and no patch is currently available.

Verified Facts

  • CVE-2026-5027 is a path traversal vulnerability in Langflow with CVSS score 8.8
  • The vulnerability is actively exploited in the wild
  • Exploitation allows unauthenticated attackers to write files to arbitrary locations
  • No patch is currently available

Evidence

  • CVE-2026-5027
  • VulnCheck analysis
  • Active exploitation reports from The Hacker News, BleepingComputer, and SecurityWeek

Impact

Organizations using Langflow in exposed environments are at immediate risk of full compromise. Defenders should isolate or disable Langflow instances until a patch is released.

Confidence Level: High

The Hacker News | BleepingComputer | SecurityWeek

2. CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog; Issues New Patching Directive

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-20245 (Cisco Catalyst SD-WAN Manager), a Chrome vulnerability, and an Arista flaw. Concurrently, CISA issued Binding Operational Directive 26-04, requiring federal agencies to patch critical exploited vulnerabilities within three days.

Verified Facts

  • CVE-2026-20245 (CVSS 7.8) is an improper encoding/escaping vulnerability in Cisco Catalyst SD-WAN Manager
  • CISA added three vulnerabilities to KEV catalog on June 10, 2026
  • CISA issued Binding Operational Directive 26-04 requiring patching of critical exploited flaws within 3 days
  • The directive applies to Federal Civilian Executive Branch agencies

Evidence

  • CVE-2026-20245
  • CISA KEV catalog update
  • CISA Binding Operational Directive 26-04

Impact

Defenders should prioritize patching these vulnerabilities within the mandated timeline. The directive signals increased urgency for all organizations to accelerate patch management for actively exploited flaws.

Confidence Level: High

The Hacker News | BleepingComputer

3. China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Botnet network of IoT devices with cyber attack overlay

The JDY botnet, associated with Chinese state-sponsored threat actors including Volt Typhoon, has expanded to over 1,500 SOHO and IoT devices. The botnet operates as a centrally controlled scanner for discovering and mapping exposed services, with a focus on U.S. military networks.

Verified Facts

  • JDY botnet comprises over 1,500 SOHO and IoT devices
  • Associated with China-nexus state-sponsored threat actors including Volt Typhoon
  • Used for high-performance scanning and reconnaissance of exposed services
  • Targeting includes U.S. military networks

Evidence

  • Lumen Technologies research
  • Reports from The Hacker News and BleepingComputer

Impact

The expansion of JDY indicates increased reconnaissance capabilities against critical infrastructure and military networks. Defenders should monitor for scanning activity from compromised SOHO/IoT devices and review exposure of management interfaces.

Confidence Level: High

The Hacker News | BleepingComputer

Also Noted

OceanLotus (APT32) continues active espionage campaigns targeting Vietnamese government entities and diaspora organizations. Monitoring recommended for organizations with Vietnamese operational ties.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings