Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: actively-exploited (105 articles)Clear

Attackers exploit critical VMware vCenter flaw to plant reverse SSH backdoors

A critical VMware vCenter flaw that Broadcom patched in late July is now under active exploitation in a global campaign. Tracked as CVE-2026-59310 and scored 9.8, it is a directory-traversal bug in the vCenter Syslog server that lets an unauthenticated attacker with network access run code, turning a logging service into a route onto the host. Incident responders at QUIRSO found a single actor exploiting it from around August 3, using path traversal to drop a cron job that launches the open-source reverse_ssh tool for persistent remote access. More than 360 compromised systems across 47 countries have been identified, and patching alone will not remove an existing foothold.

Check
Apply Broadcom's vCenter update immediately if you have not, since there is no workaround, and hunt compromised hosts for unexpected cron jobs, the reverse_ssh tool, and unusual outbound SSH connections.
Affected
Organizations with network-reachable VMware vCenter on unpatched builds (CVE-2026-59310); an unauthenticated attacker can run code on the appliance, and this campaign installs a reverse SSH backdoor that survives patching.
Fix
Patch, then investigate for compromise rather than assuming the update suffices, remove any reverse_ssh persistence and rogue cron jobs, restrict vCenter access, and review logs for path-traversal requests to the syslog service.

Exploited Metabase zero-day gives unauthenticated attackers admin and database credentials

Metabase warned that a critical zero-day in its open-source business intelligence platform was exploited in the wild for data theft. Scored 10.0 and tracked only as GHSA-vwf4-m7j8-wcjf with no CVE assigned, so scanners relying on the national database will not flag it, the flaw is an unauthenticated SQL injection in the password-reset endpoint. A remote attacker with no credentials injects SQL into the application database, gains administrator access, and can steal the stored credentials for every database the instance connects to, then read and export their data. Metabase Cloud was attacked from around August 3 and is already patched; self-hosted versions 1.58 and later must upgrade.

Check
Upgrade self-hosted Metabase to the fixed release for your branch immediately, and if the reset-password endpoint was internet-reachable, treat the instance and all connected database credentials as compromised.
Affected
Organizations running self-hosted Metabase 1.58 or later; an unauthenticated attacker can gain admin access and steal credentials for every connected database, and it is exploited with no CVE for scanners to catch.
Fix
Patch to the safe release, clear the session table to revoke sessions, rotate credentials for all connected databases, audit API keys and admin accounts, and block the reset-password endpoint if unpatched.

Progress Kemp LoadMaster command injection flaw added to KEV after active exploitation

CISA added a critical Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Tracked as CVE-2026-8037 and scored 9.6, it is a command injection bug that lets an unauthenticated attacker run arbitrary commands on the load balancer appliance through unsanitized input in several command endpoints. watchTowr traced it to improper handling of user input in a quote-escaping function. Telemetry recorded 792 exploitation attempts over 41 days from 65 addresses across 18 countries, with activity as recent as early August. Federal agencies were directed to patch by August 10, a useful signal of urgency for everyone else.

Check
Patch Progress Kemp LoadMaster appliances to the fixed release now, and because the appliance sits inline with traffic, review it for signs of command execution and unexpected configuration changes.
Affected
Organizations running unpatched Progress Kemp LoadMaster (CVE-2026-8037); an unauthenticated attacker can execute arbitrary commands on an appliance that sits inline with network traffic, and exploitation is ongoing.
Fix
Apply the vendor patch, restrict management access to the appliance, hunt for unauthorized commands and configuration changes, and rotate any credentials the load balancer stored or handled.

Attackers exploit N-able RMM auth bypass, and the first fix did not hold

N-able is warning that attackers exploited an authentication bypass in N-central, the remote monitoring and management platform used by managed service providers and IT teams to administer customer endpoints. The flaw, CVE-2026-18556, allows unauthenticated administrative account takeover, and N-able's initial fix in one release proved incomplete: it found another way to exploit the same weakness, tracked as CVE-2026-18577, that widened the affected range. After taking over a server, attackers used its remote-control feature to reach managed endpoints and installed Cloudflare tunnels as services, which kept access alive even after the route through the N-central server was cut. Build 2026.3.1.7 is the first unaffected version.

Check
Upgrade N-central to build 2026.3.1.7 immediately, then hunt managed endpoints for unexpected Cloudflare tunnel services and other persistence, since patching the server does not remove footholds already placed.
Affected
Managed service providers and IT teams running N-able N-central before build 2026.3.1.7 (CVE-2026-18556, CVE-2026-18577); an unauthenticated attacker can take over the server and pivot to every managed customer endpoint.
Fix
Apply the hotfix, review N-central and endpoint logs for unauthorized access and tunnel installs, revoke and rebuild trust where compromise is found, and restrict management platform exposure to the internet.

INC ransomware becomes the main group exploiting SonicWall VPN appliances

Resecurity reports that the INC ransomware operation has become the dominant group exploiting two SonicWall SMA1000 VPN appliance flaws, accelerating its attacks since early August. The pair, CVE-2026-15409 and CVE-2026-15410, were exploited as zero-days before SonicWall patched them in mid-July, and can be chained to gain root on the appliance and extract credentials, session databases, and one-time-password data. Many appliances remain unpatched or already compromised, leaving footholds attackers can reuse. Victims listed recently span private and government organizations across several countries, and some reported follow-up emails and phone calls from people claiming to help with the ransomware.

Check
Confirm SonicWall SMA1000 appliances have the mid-July fixes, and because pre-patch exploitation was common, run a compromise assessment and rotate credentials, sessions, and one-time-password secrets the appliance handled.
Affected
Organizations running SonicWall SMA1000 appliances (CVE-2026-15409, CVE-2026-15410); INC ransomware is actively chaining the flaws to root devices, and unpatched or already-compromised appliances remain reusable footholds.
Fix
Patch, then re-image compromised appliances and reset all credentials and one-time-password tokens they processed, restrict management access, and treat unsolicited offers of ransomware help as part of the extortion.

Cisco patches exploited Firewall Management Center flaw that grants built-in account access

Cisco has patched a flaw in Secure Firewall Management Center that attackers were already exploiting to log into devices. Tracked as CVE-2026-20316, it stems from static credentials for a low-privilege account built into the software, letting an unauthenticated remote attacker sign in and read sensitive data. Cisco scored it 5.3 but rated it High because the access can be chained with other flaws to escalate privileges. In the same cycle it patched CVE-2026-20079, a separate critical authentication bypass that reaches root, and shipped one set of hot fixes with a shared indicator suggesting the two could be combined. There are no workarounds.

Check
Upgrade Secure FMC to a fixed release now, and check for compromise by searching device logs for references to /var/tmp/license.tmp, which Cisco lists as an indicator.
Affected
Organizations running Cisco Secure Firewall Management Center releases 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0 (CVE-2026-20316); the flaw is exploited, and chaining with the root-level bypass raises the stakes.
Fix
Apply Cisco's hot fixes, since there is no workaround, keep the FMC management interface off the public internet, and if the indicator appears, rotate all device credentials, keys, and certificates.

Critical Arista VeloCloud Orchestrator flaw exploited in attacks

Arista patched a critical vulnerability in on-premises VeloCloud Orchestrator, the console that configures and manages VeloCloud SD-WAN deployments, that is already being exploited. Tracked as CVE-2026-16812 and scored 10.0, it is an unauthenticated operating-system command injection that lets a remote attacker reach privileged functionality meant only for internal use. Arista warns successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and everything it manages. There is no configuration that prevents exposure, since the web interface is reachable by default. CISA added it to its exploited-vulnerabilities catalog. Hosted and Dedicated deployments were fixed before the advisory and are not affected.

Check
Identify on-premises VeloCloud Orchestrator instances, upgrade to the fixed 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.x releases immediately, and restrict the web interface to trusted administrative networks.
Affected
Organizations running on-premises VeloCloud Orchestrator (CVE-2026-16812); the web interface is exposed by default, needs no credentials, and active exploitation gives attackers command execution over the orchestrator and managed devices.
Fix
Upgrade to the fixed VCO versions, limit web interface access to trusted networks, and review VCO web access logs for unusual path components, encoded characters, or high request rates.

Check Point patches exploited SmartConsole flaw giving attackers full admin access

Check Point has fixed an actively exploited flaw in SmartConsole, the graphical admin panel used to manage its security products. CVE-2026-16232, rated 9.3, is an authentication bypass letting an unauthenticated remote attacker obtain a login token and authenticate with administrator privileges, after which they can alter security configuration and policy on a Security Management or Multi-Domain Management server. Exploitation requires the management server to be reachable from the internet with no restrictions on trusted GUI clients. The same update fixes a second critical authentication bypass and a Gaia Portal issue letting read-only users run commands as root.

Check
Install the July 22 Jumbo hotfix on Security Management and Multi-Domain Management servers, then restrict trusted GUI clients to approved addresses and firewall management access to known sources.
Affected
Organizations running Check Point Security Management or Multi-Domain Management with the console reachable from the internet (CVE-2026-16232); attackers gain administrator access and can rewrite the security policy protecting the network.
Fix
Apply the hotfix, limit trusted clients to specific addresses, keep management interfaces off the public internet, and review policy changes and administrator logins for unauthorized modifications.

Attackers exploit Windmill flaw to read server files and reach superadmin access

VulnCheck reports active exploitation of a path traversal flaw in Windmill, an open source platform for building internal tools, jobs, and workflows. CVE-2026-29059 lets an unauthenticated attacker read arbitrary files through the log file endpoint, and while observed attempts included reading the password file, the higher value target is the superadmin secret. Where that is configured, an attacker can authenticate as a super administrator and run arbitrary code through the job preview API. VulnCheck counted roughly 170 exposed instances across 24 countries, including deployments reachable through a proxy path rather than directly.

Check
Update Windmill to a fixed release, confirm whether any instance was reachable from the internet, and treat the superadmin secret and any credentials stored in configuration as exposed.
Affected
Organizations running internet-reachable Windmill deployments (CVE-2026-29059); unauthenticated attackers read server files, and where the superadmin secret is set, escalate to full administrative access and code execution.
Fix
Patch to the fixed version, rotate the superadmin secret and stored credentials, keep internal automation platforms off the public internet or behind authentication, and review logs for file read attempts.

Attackers steal SharePoint machine keys in one request after exploit code goes public

Attackers began exploiting a critical Microsoft SharePoint flaw within days of a working proof-of-concept appearing publicly. CVE-2026-50522 is a deserialization of untrusted data issue rated 9.8 that lets a remote attacker run code on on-premises SharePoint without authentication, and Microsoft patched it in the July updates while marking exploitation as more likely rather than confirmed. Offensive security firm watchTowr reports active attacks against on-premises deployments, with attackers pulling SharePoint machine keys in a single request. Those keys let an attacker forge authentication tokens and impersonate users, so access survives patching. It is the third SharePoint flaw to see exploitation this month.

Check
Apply July's SharePoint updates, then rotate machine keys on any on-premises server that was internet-reachable, since patching alone does not evict an attacker who already pulled them.
Affected
Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition (CVE-2026-50522); unauthenticated attackers run code and steal machine keys that let them forge tokens and keep access after patching.
Fix
Patch, rotate machine keys and any credentials the server handled, hunt for web shells and forged token use, and restrict internet exposure of on-premises SharePoint deployments.