■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement ■ GET-IT Intelligence

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses — plus analysis and commentary from GET-IT. Curated from NCSC, CISA, FCA ScamSmart, ICO intelligence feeds, and our own research.

[ LAST UPDATED: 20 June 2026 at 10:26 UTC ]
█ New — MITRE-Lite Weekly

Our plain-English translation of the MITRE ATT&CK framework — who is targeting UK businesses this week, how they operate, and what to do about it. Updated every Monday.

Business Owner Edition → Technical Edition →

Analysis & Commentary

All GET-IT analysis & news →

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC THU, 18 JUN 2026

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Read NCSC Advisory →
NCSC THU, 18 JUN 2026

The 'vibe coding spectrum' approach to AI-assisted software development

Read NCSC Advisory →
NCSC WED, 17 JUN 2026

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems

Read NCSC Advisory →
NCSC THU, 04 JUN 2026

Software supply chain attacks: check your dependencies

Read NCSC Advisory →
NCSC WED, 27 MAY 2026

Designing secure access with ZTNA

Read NCSC Advisory →
NCSC FRI, 15 MAY 2026

Thinking carefully before adopting agentic AI

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-06-18
CVE-2026-20253 — Splunk | Enterprise

Splunk Enterprise Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

View CISA Advisory →
CISA KEV CRITICAL 2026-06-16
CVE-2026-48907 — Widget Factory | Joomla Content Editor

Widget Factory Joomla Content Editor Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

View CISA Advisory →
CISA KEV CRITICAL 2026-06-15
CVE-2026-54420 — LiteSpeed | cPanel Plugin

LiteSpeed cPanel Plugin Vulnerability

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

View CISA Advisory →
CISA KEV CRITICAL 2026-06-15
CVE-2026-20262 — Cisco | Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

View CISA Advisory →
CISA KEV CRITICAL RANSOMWARE KNOWN 2026-06-12
CVE-2026-35273 — Oracle | PeopleSoft Enterprise PeopleTools

Oracle PeopleSoft Enterprise PeopleTools Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

View CISA Advisory →
CISA KEV CRITICAL 2026-06-11
CVE-2026-10520 — Ivanti | Sentry

Ivanti Sentry Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD MONDAY, JUNE 8,

FCA secures confiscation order against Ponzi scheme fraudster

The FCA has secured a confiscation order of £452,286.80 against convicted fraudster Daniel Pugh. Mr Pugh, 36, is serving a 7 years and 6 months prison sentence for defrauding investors out of £1.3m.Run from his bedroom...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, JUNE 8,

Consumers warned about misleading car finance 'money tips' claims ads

Consumers are being warned to be wary of misleading car finance 'money tips' adverts issued by claims management companies (CMCs) and law firms on social media. As part of the joint regulatory taskforce, the FCA has ide...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD WEDNESDAY, JUNE

Football clubs warned about questionable sponsorship deals with unauthorised financial firms

Football clubs have been warned not to put their fans’ cash at risk by signing sponsorship deals with financial firms that aren't allowed to operate in the UK. According to the FCA, a number of unauthorised firms, inclu...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.