Cyber Exposure Alerts

Cyber Exposure Alerts From Tenable

  • Edge infrastructure under siege: what two independent datasets reveal about who’s exploiting your perimeter
    by Research Special Operations on August 26, 2026 at 9:00 am

    A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs.Key TakeawaysTwo independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap.Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware).The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix.54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch.Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers.The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months.Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access.The convergence is the storyTwelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern:CVEProductActors (Nexus)SignificanceCVE-2026-15409SonicWall SMA1000UTA0533 (unattributed) + INC RansomwareEspionage-to-ransomware succession on an active zero-dayCVE-2023-42793JetBrains TeamCityAPT29 (Russia) + Lazarus (DPRK)Two state-sponsored actors from different nations on the same CVECVE-2024-3400PAN-OS GlobalProtectUTA0218 (China) + INC RansomwareChina-nexus zero-day reused by ransomware operatorsCVE-2024-24919Check Point QuantumPurpleHaze (China) + Fox Kitten (Iran)China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor’s activity, is the finding.That pattern holds across the full combined analysis. Three conclusions emerge:Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta’s React framework) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patching the current CVE does not remove the vendor attack surface from the threat landscape.State-sponsored and ransomware actors converge structurally. Twelve CVEs with confirmed multi-nexus attribution span all five nexus categories and cross the state-criminal divide. Defending against one actor category on edge devices necessarily requires defending against all of them, because the attack surface is shared. An organization that patches only for nation-state TTPs leaves itself exposed to ransomware operators exploiting the same vulnerability, and vice versa.High-priority CVEs take more time to remediate, not less. Across Tenable’s 238-CVE high-priority list, high-priority CVEs carry a median remediation time of 146 days, compared to 122 days for all other CVEs — a 24-day gap that is statistically significant. The edge-appliance-specific subset (52 CVEs) shows a consistent 8-day gap in the same direction, which was not statistically significant, but suggests the direction may hold for edge appliances too. External data corroborates the pattern: the 2026 Verizon Data Breach Investigations Report (DBIR) found that median patch time increased from 32 to 43 days year over year, even as exploitation overtook credential theft as the number one initial access vector, and the 2025 DBIR, which incorporated Tenable RSO’s remediation trend analysis across 17 edge-related CVEs, found that only 54% of edge device KEVs were fully remediated. The explanation is structural: edge devices are the network boundary, so patching a VPN gateway or firewall means downtime for every user behind it, and change management gates multiply. These devices also resist standard patching workflows because they do not run endpoint agents, often require firmware-level updates with manual validation, and frequently lack active support contracts. The result is that the devices most worth patching are operationally the hardest to patch — and as the high-priority queue grows (the 2026 DBIR reports 50% more critical vulnerabilities to patch than the prior year), everything on it waits longer.BackgroundEdge and perimeter devices occupy a uniquely consequential position in enterprise architecture. VPN gateways, firewalls, remote access appliances, and application delivery controllers sit at the boundary between trusted and untrusted networks. They are very often the first component an attacker touches and, for many organizations, the last component that gets patched. When one of these devices is compromised, the attacker inherits its network position: inside the perimeter, with access to internal resources, often without triggering endpoint detection.This analysis combines two independent datasets to demonstrate that convergence. Tenable contributes exposure telemetry from the Tenable One Exposure Management Platform, covering thousands of customer containers and measuring what edge infrastructure is deployed, what is vulnerable, and how long it remains unpatched. This dataset extends Tenable Research’s ongoing analysis of edge device exposure trends, including the remediation telemetry Tenable contributed to the 2025 and 2026 Verizon DBIR reports. SentinelOne contributes findings from its digital forensics and incident response (DFIR) practice, documenting which threat actors actually exploit which vulnerabilities, observed firsthand inside compromised environments. Neither dataset was built for this analysis; each was constructed independently for different operational purposes.The finding that makes this analysis compelling is not about any single CVE or any single actor. It is the structural convergence: two independent observation systems, looking at the problem from opposite sides, arrive at the same conclusion about which vendor surfaces are under persistent, broad exploitation, and by whom. (For how each dataset was built and scored, see the Methodology appendix below.)What’s exposed: the vulnerability surfaceTenable’s exposure telemetry provides the vulnerability-side view. All exposure metrics reported here use container-grain measurement: the percentage of customer environments (organizational containers) with at least one asset vulnerable to a given CVE as of Aug. 15, 2026, relative to total exposed containers over the preceding 14-month period. This measures breadth of organizational exposure to edge-product vendor vulnerabilities, not raw asset counts, across the sampling window.This section covers 15 vendors in three groups: seven confirmed in both independently compiled corpora, two confirmed in SentinelOne’s casework but absent from Tenable’s attributed corpus, and six “candidate” vendors surfaced by a broader screen of Tenable telemetry. The candidates are not part of the convergence finding, but two, F5 and Zimbra, show broader customer exposure than most of the confirmed seven, so omitting them would understate the breadth of at-risk edge infrastructure.[FIGURE: Current vendor-level exposure heat map (container-grain, 15 vendors). Proportion of historically-exposed containers with at least one asset actively exposed to one or more relevant CVEs. Source: Tenable exposure telemetry.]F5 and Citrix lead for different reasons. Among vendors with statistically robust sample sizes, F5 customers are the most broadly exposed: 53.8% of 2,784 monitored customer environments running F5 products have at least one actively exploited CVE present. Citrix customers show the slowest remediation patterns: a median of 461 days to patch, with 71% of affected environments still carrying unpatched Citrix CVEs after a full year. F5 leads on scale of exposure; Citrix leads on persistent exposure.The mid-pack is flatter than expected. Check Point (18.6%), Ivanti (24.1%), Fortinet (24.9%), and Citrix (28.8%) cluster within a 10-point band at container-grain. Fortinet, which dominates headlines, is mid-pack by this measure.Thin-sample vendors show extreme rates but require caution. Juniper (91.7%), VMware (75.0%), Palo Alto Networks (69.2%), and Cisco (56.2%) all show container-exposure proportions above 50%, but each has fewer than 50 in-sample containers. These statistics are real directional signals, but should be considered within the context of the relatively low sample size.Serial exploitation is structural. Two clean serial-exploitation sequences appear in the dataset: Ivanti EPMM (approximately 8.5 months between successive exploited CVEs) and Ivanti Connect Secure (approximately 13 months). Same product line, new vulnerability, repeat exploitation. Tenable Research has published advisories on both Ivanti exploitation sequences, tracking each CVE from initial disclosure through active exploitation, and the exposure data here extends that analysis with organizational remediation timelines not available at the time of the original advisories. The next one is coming.Who exploits what: the threat actor landscapeThis is not a targeted effort by a specific group. Edge infrastructure is a core focal point of attack across a broad range of threat actors and nexus categories. The combined Tenable-SentinelOne corpus documents exploitation by actors spanning five nexus categories: China, Russia, DPRK, Iran, and criminal (financially motivated). All five categories independently target the same vendor surfaces. Every attribution in the corpus is bucketed into one of three confidence tiers derived from a five-dimensional rubric evaluating attribution directness, evidence provenance, recency, exploitation role, and source corroboration. Confidence tiers, from high to low, are: DIRECT, TECHNIQUE-ALIGNED, or INFERRED.Actor density scales with vendor exposure. Fortinet products face the broadest actor surface: 29 distinct threat actors across five nexus categories. Citrix follows with 22 actors across five categories, Ivanti with 19 across four, Palo Alto Networks with nine across three, and Check Point with six across two. Every focal vendor has confirmed exploitation from multiple nexus categories. No single vendor’s exposure is attributable to a single adversary group.China-nexus actors are the highest-confidence case study, appearing across nine vendors in the corpus, with four DIRECT-tier attributions from the scored dataset alone. But the analytical value here is not that China targets edge devices. That is well established. The value is that China, Russia, DPRK, Iran, and ransomware operators all target the same edge devices, as the examples above illustrate. The governed attribution methodology is what allows this claim to be made with precision: we can distinguish confirmed multi-nexus convergence (DIRECT-tier evidence on both sides) from assessed convergence (INFERRED, requiring corroboration).What incident response sees that telemetry can’tExposure data shows which appliances are reachable, vulnerable, and unpatched. Incident response looks at what happened when attackers got in: what they accessed, what they took, and where they went next. In SentinelOne DFIR cases involving edge infrastructure, attackers used credentials stored on the appliances and the access those appliances already had to reach internal systems.Credential theft from edge appliancesAcross three engagements, threat actors reached the management plane of FortiGate appliances and created rogue administrative accounts. In two, they also exported device configurations and extracted credentials that could be used to move further into the network. Two of these three are documented in detail in FortiGate Edge Intrusions.In one of those two, the exported configuration contained LDAP bind credentials for a directory service account. The account was later used in the environment. A few hours later, the threat actor added two computers to the domain. Neither had a Service Principal Name, which is unusual for a legitimate domain join. The mS-DS-CreatorSID attribute on both accounts pointed back to the stolen service account.We saw similar activity on an Ivanti Cloud Services Appliance in late 2024. A China-nexus actor chained CVE-2024-8963 with CVE-2024-8190 before the first public disclosure in the chain. After gaining access, the actor collected SSH keys and other stored credentials. That engagement is documented as Activity F in Follow the Smoke.These appliances did not provide conventional endpoint telemetry. We had to follow the activity into authentication records, newly created Active Directory objects, and the later use of credentials taken from the appliances.When the initial access vector cannot be confirmedIn December 2025, Fortinet disclosed CVE-2025-59718, an authentication bypass in its FortiCloud SSO integration affecting FortiOS and other products. Several weeks later, Fortinet disclosed CVE-2026-24858. This second flaw allowed an attacker with a FortiCloud account and a registered device to log into devices belonging to other customers when FortiCloud SSO was enabled.That overlap mattered in one of the three engagements above. The appliance was running a version affected by both CVEs, but the available logs did not show when or how the attacker first gained access. The earliest retained malicious activity showed a rogue local administrator account. A few minutes later, a domain administrator authenticated from the appliance’s VPN address pool. Exposure data showed that the appliance had been vulnerable to both CVEs, but that alone did not establish how it was compromised. We treated both as possible, not confirmed, initial-access vectors.Abuse of trusted management accessIn one SentinelOne DFIR engagement involving a FortiManager appliance, CVE-2024-47575 allowed an unauthorized device to register with the appliance through the management protocol. Two log entries, seconds apart, recorded the rogue registration and the settings change that followed. The threat actor then staged an archive of managed-device configurations that could expose credentials, addresses, and details about the network. The actor had been present for about a month before the customer detected the activity.In a separate engagement, a threat actor chained SQL injection, pass-the-hash authentication, and authentication bypass against an internet-facing SonicWall GMS console (CVE-2023-34133, CVE-2023-34132, and CVE-2023-34124). The actor created administrative accounts on a platform operated by a managed service provider, then used existing shared access to enter multiple customer environments. Most of the resulting traffic was advertising-related, leading us to assess that the infrastructure was being used for click fraud.The actors were after different things. One collected configuration data and information about the network. The other used the access to turn systems across several environments into proxies. In both cases, the actor inherited the access that the organization had already granted to the management platform. These cases show the difference between the two views: exposure telemetry finds the vulnerable device, while incident response shows what was taken from it and where the attacker went next.What to do about itPatch F5 and Citrix edge devices immediately. These two vendors combine the highest exposure rates with the slowest remediation timelines across statistically robust samples. Look for strategies to reduce the remediation time, particularly for weaponized CVEs. Additionally, reduce the attack surface by minimizing the enabled feature set on these devices and aim for defense in depth by running endpoints in protect mode to limit lateral movement opportunities.Audit Ivanti Connect Secure and EPMM deployments. Serial exploitation on observed 8.5 to 13-month cycles means the next exploitable CVE in these product lines is a question of timing, not probability. Organizations running Ivanti edge products should assume they will face a new actively exploited vulnerability within the next year and plan patching capacity accordingly.Implement edge-device-specific patch SLAs. The delayed remediation paradox demonstrates that general priority frameworks do not translate into faster patching on the devices that sit at the network boundary. Edge devices and network infrastructure warrant dedicated remediation timelines that are shorter than the organizational default and commensurate with the elevated risk.Treat edge device exposure as a cross-signal priority. Attribution, severity, and exposure volume identify different CVEs as “top priority.” Organizations need all three signals for complete coverage. A vulnerability management program that prioritizes exclusively by CVSS will systematically underweight CVEs with strong exploitation evidence but modest severity scores, and vice versa. The Tenable One Exposure Management Platform enables this cross-signal approach by combining vulnerability severity, exposure intelligence, asset context, and exposure data into a unified prioritization view.Identifying affected systemsTenable customers can use the Tenable Vulnerability Watch dashboard to monitor classifications for all CVEs discussed in this analysis. A list of Tenable plugins for the vulnerabilities discussed in this analysis can be found on the individual CVE pages at tenable.com/cve as they are released. This link displays all available plugins for each vulnerability, including upcoming plugins in our Plugins Pipeline.Get more informationTenable Vulnerability WatchSentinelOne – What two independent datasets reveal about who’s exploiting your perimeterSentinelOne Threat Research (PurpleHaze, SonicWall SMA1000)FortiGate Edge Intrusions – SentinelOneFollow the Smoke – SentinelOneCISA Known Exploited Vulnerabilities CatalogJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.Appendix: Methodology and corpus constructionHow the corpus was built. Tenable’s 33-CVE corpus was derived by combining and deduplicating vulnerabilities with the highest exploitation volume and broadest actor adoption; SentinelOne validated CVEs across 14 vendors, and their 66-CVE landscape view reflects 12 months of DFIR casework with false positives removed. Combined, the two datasets identify 82 distinct CVEs, 17 of which appear in both. Layered on top of these sources is a governed attribution corpus of 93 CVE-actor pairs spanning approximately 39 named threat actors and five nexus categories.Why Tenable tracks these CVEs. Tenable’s set comes out of exposure management. A CVE enters it through the Vulnerability Watch program, which classifies vulnerabilities under active or likely to be exploited, and is additionally scored with a Vulnerability Priority Rating (VPR). The question being answered is prescriptive: of everything actually deployed across customer environments, what should be prioritized and patched first? Threat-actor attribution is layered on afterward from definitive and confidence-scored sources (e.g., Federal cybersecurity advisories).Why SentinelOne tracks these CVEs. SentinelOne’s set comes from the opposite direction: incident response. A CVE earns its place in their 12-month DFIR landscape because responders found it used in a real intrusion — the initial access vector in a case someone called them about. The question being answered is forensic: what happened here, and who did it? Coverage is shaped by who engaged them, not by install base.What “overlap” means here. Overlap was measured at two levels, and the answer changes sharply depending on which level you use.At the level of the individual vulnerability, the two sets barely intersect. Only 17 of 82, or 21%, of CVEs are common to both. Tenable and SentinelOne are, for the most part, not looking at the same vulnerabilities. However, the datasets converge at the product level. Eleven of the 14 vendors in Tenable’s focal CVE set appear in SentinelOne’s 12-month DFIR landscape – a 79% convergence: Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta’s React framework. That’s 79% convergence at the vendor level against 21% at the CVE level. Three vendors did not conform: Apache and SAP were absent from SentinelOne’s casework, and the one Progress case they worked on was closed as a false positive. Narrow the comparison to edge and remote-access infrastructure specifically, and the convergence is a perfect 100%. Tenable’s corpus independently identified seven edge vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware). All seven appear in SentinelOne’s casework. Two teams, working from unrelated evidence for unrelated purposes, arrived at the same seven vendors while sharing roughly one CVE in five.Why the distinction matters. “Different vulnerabilities, same vendors” is not a weaker version of “same vulnerabilities.” It is a different and more actionable claim. Had both datasets converged on the same individual CVEs, the story would be that a specific handful of vulnerabilities is being widely exploited: patch those and the problem shrinks. What the data actually shows is that state-sponsored and criminal operators are independently arriving at the same small set of edge and remote-access product vendors, then finding their own separate ways in. The durable target is the vendor attack surface. Patching this quarter’s Ivanti CVE does not remove Ivanti from anyone’s target list.All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third party.

  • Frequently asked questions about the active threat to Siemens S7 Series PLCs
    by Research Special Operations on August 20, 2026 at 10:01 am

    A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine exploit scripts faster than manual development would allow. AI use lowers the technical bar for ICS attacks in a way defenders haven’t had to plan for before.There is no single patch, because there is no single flaw. Mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks and hardening access controls.BackgroundOn August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well.According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together this frequently asked questions (FAQ) blog to help security and OT teams understand the threats, the techniques involved and the mitigations offered by the authoring agencies. The advisory itself notes that ongoing PLC targeting is broader than Siemens alone and that all PLC owners and operators, regardless of vendor, should apply all relevant mitigations.FAQWhat is the active threat to Siemens S7 Series PLCs?The advisory describes coordinated reconnaissance and capability-development activity against Siemens S7 Series PLCs that are internet-exposed or poorly segmented. According to the authoring agencies, the threat actors combine internet scanning services with AI-assisted scripting to build custom tools that can read and write PLC memory, configuration data, and ladder logic programs over the S7comm protocol, while masquerading as legitimate monitoring software.The agencies assess the activity as persistent reconnaissance intended to develop capabilities and pre-position for future disruptive attacks against critical infrastructureWhich Siemens PLC models are being targeted?The advisory identifies five Siemens S7 Series product lines as targets:SeriesVariants targetedS7-200All CPU variantsS7-300All CPU variants, including the 314, 315 and 317 modelsS7-400All CPU variantsS7-1200CPU 1211C, 1212C, 1214C, 1215C and 1217C variantsS7-1500All CPU variants including F-series safety controllers How is this different from the Iranian-linked PLC campaign covered in AA26-097A?In April 2026, CISA and its partners, including NSA, the FBI, EPA, DOE, U.S. Cyber Command, and the Treasury Department, issued and later expanded cybersecurity advisory AA26-097A, which detailed a campaign publicly linked to Iran-affiliated actors tracked as CyberAv3ngers. That campaign exploited internet-exposed PLCs from Rockwell Automation, Schneider Electric and Siemens using the vendors’ own engineering software to manipulate readings and exfiltrate project files. The updates to that advisory were made just days before the news of attacks involving several water districts, including those in Minnesota. For more information on these attacks, please refer to the RSO blog; Coordinated “cyberattack” on U.S. water utilities: What you need to know.This new advisory covers a distinct activity pattern specifically centered on the Siemens S7 Series devices. The authoring agencies do not attribute these attacks to any named threat actor or group. The techniques described in this advisory describe threat actors leveraging AI to design scripts built on open-source industrial automation libraries, including snap7.dll, disguising these scripts as monitoring tools. Organizations should treat the two advisories as related but separate threats to the same class of equipment, and should apply the mitigations in both if they operate Siemens S7 Series PLCs. However, as the advisory points out, regardless of which PLCs your organization may operate, the recommendations are to apply the proper mitigations to help secure these devices, including mitigations from this guide.Which threat actors are behind this activity?The authoring agencies have not attributed this activity to a specific named threat actor or group. The advisory refers to the activity generically as being conducted by “threat actors” and describes confirmed reconnaissance, tool development and read/write operations against target PLCs without confirmed attribution to a tracked group. Tenable’s RSO team will update this post if attribution information becomes available.What is new about the AI-assisted exploitation described in the advisory?According to the advisory, attackers are using AI to generate exploitation scripts, demonstrating a new capability dimension in the PLC targeting. The advisory describes threat actors combining publicly available open source industrial automation libraries (specifically snap7.dll and python-snap7) with AI-assisted scripting to create custom tools. These tools could be leveraged to provide read/write access to Siemens S7 Series PLC memory, configuration data and ladder logic programs via the S7comm protocol.This represents an evolution in OT threat actor capabilities. AI dramatically reduces the technical expertise required to develop working ICS exploitation tools. Building functional S7comm exploitation scripts previously required specialized protocol knowledge and threat actor use of AI collapses that barrier. Coupling these capabilities with internet accessible devices provides attackers with abundant resources to test, iterate and rapidly improve their exploits.Are specific CVEs associated with this advisory?No individual CVE identifiers are named in the advisory. Instead, the authoring agencies state that if these PLCs are exposed to the internet or insufficiently segmented, threat actors “can exploit various critical and high severity known vulnerabilities.” The advisory directs owners and operators to consult Siemens ProductCERT advisories for model and firmware-specific vulnerability details or mitigation options if patches are not available or cannot be immediately applied.Does this involve zero-day exploitation?No. The advisory describes exploitation of known vulnerabilities, weak or default credentials and unnecessary internet exposure, not a previously unknown or undisclosed flaw. The novel element the authoring agencies highlight is the use of AI to generate and rapidly iterate exploitation scripts and evasive tooling, not zero-day exploitation of an undisclosed vulnerability.What techniques are the threat actors using?The advisory maps the observed activity to the MITRE ATT&CK Matrix for ICS and MITRE ATT&CK Matrix for Enterprise frameworks:TacticTechniqueIDReconnaissanceScanning services to find exposed PLCsT1596.005Resource DevelopmentDeveloping exploits to target known Siemens S7 Series vulnerabilitiesT1587.004Resource DevelopmentAI-assisted development of exploit codeT1588.007Lateral MovementAccessing devices with default or improperly configured credentialsT1694ExecutionAbuse AI-generated Python scripts developed using the snap7.dll libraryT0834ExecutionWrite operations on data blocksT0821EvasionMasquerading malicious scripts as legitimate monitoring toolsT0849CollectionPerform reconnaissance by reading controller dataT0893 Is there a proof-of-concept or working exploit code available?The threat actors described in the advisory have functional, custom-built exploitation tooling in active use; this is not an unconfirmed or theoretical capability. However, the authoring agencies have not published this tooling and Tenable is not aware of a publicly available proof-of-concept (PoC) tied to this specific campaign as of the date this blog was published. Because the actors are using AI to generate and rapidly iterate their own scripts, organizations should not treat the absence of a public PoC as a reason to deprioritize mitigation.What are the potential operational impacts?The advisory outlines several potential consequences of unauthorized PLC access:Disruption of critical industrial processes. This can impact production throughput, product quality and public servicesSafety incidents from manipulation. This could lead to emergency shutdowns, manipulation of safety interlocks or manipulation of process parametersEquipment damage and extended operational downtimeCompromise of sensitive operational dataCascading impacts across interconnected systems, supply chains and dependent facilitiesRegulatory compliance violations tied to process safety management failuresAre patches or mitigations available?Because this activity exploits internet exposure, improper configurations and a range of known vulnerabilities, rather than a single flaw, there is no single patch that resolves all risks related to this advisory. Instead, owners and operators are recommended to contact Siemens ProductCERT for firmware updates addressing known vulnerabilities in each affected CPU family, with priority given to internet-facing or DMZ-resident controllers. Additionally, the advisory outlines seven categories of hardening action:Inventory all Siemens S7 Series PLCs and engineering workstationsApplying current firmware and TIA Portal/STEP 7 updatesVerifying segmentation and blocking TCP port 102 at the network perimeterStrengthen access controls including restricting engineering software access and enabling PLC password protection and multi-factor authentication for remote OT accessDeploying ICS-aware monitoring and loggingSecurity hardening including disabling unused protocols, web servers and default SNMP stringsEngaging Siemens Technical Support for model-specific guidanceWhat preventative actions should organizations take?Treat internet accessibility as the primary risk factor. Any Siemens S7 Series PLC reachable from the internet, directly or through a third-party integrator’s remote access path, should be treated as under active threat. Block TCP port 102 at the network perimeter and verify there is no unauthorized routing between corporate and OT networks.Apply firmware updates for your specific device models, prioritizing internet-facing and DMZ-resident controllers and test updates in a non-production environment before deployment.Restrict engineering software access. Limit TIA Portal and STEP 7 access to authorized engineering workstations through MAC/IP allowlisting, enable PLC password protection and available protection levels and require multi-factor authentication for remote access into OT networks. Ensure engineering workstations are up to date with the latest software and security updates.Monitor for the specific indicators the advisory calls out: snap7.dll or python-snap7 library usage outside approved engineering workstations, S7comm connections from non-engineering hosts, IP scanning on TCP port 102 and PUT/GET write operations to data blocks outside scheduled change windows.Identifying affected systemsTenable customers can use the Tenable One Exposure Management Platform, including Tenable One OT Exposure, to inventory Siemens S7 Series PLCs and other OT assets and prioritize remediation. Tenable One OT Exposure also provides continuous monitoring of your OT assets to provide deep visibility into your industrial control system networks and associated devices. If any individual Siemens S7 CVEs are confirmed relevant to this campaign, we will update this blog with relevant plugin coverage.Tenable customers with Tenable Security Center or Tenable One Vulnerability Management can utilize the OT Recon scan policy to identify Siemens and other OT assets.Get more informationCISA Advisory AA26-231A: Defending Against an Active Threat to Siemens S7 Series PLCsCISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical InfrastructureTenable Blog: Coordinated “cyberattack” on U.S. water utilities: What you need to knowCISA: Primary Mitigations to Reduce Cyber Threats to Operational TechnologyCISA: Secure Connectivity Principles for Operational TechnologyCISA AA22-265A: Control System Defense: Know the OpponentSiemens ProductCERTJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
    by Research Special Operations on August 18, 2026 at 8:41 pm

    Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates154 issues (16.3% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patchesBackgroundOn August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families.To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August’s CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July’s quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope.Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%.This month’s update includes 154 critical patches across 151 CVEs.SeverityIssues PatchedCVEsCritical154151High556541Medium198198Low3535Total943925AnalysisThis month’s update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, accounting for 27.8% of the total patches, followed by Oracle Hyperion at 262 patches, which accounted for 27.8% of the total patches.A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle Fusion Middleware262182Oracle Hyperion262107Oracle E-Business Suite12027Oracle Commerce6647Oracle Siebel CRM5021Oracle Supply Chain4618Oracle Virtualization212Oracle Analytics163Oracle PeopleSoft157Oracle Communications139Oracle Enterprise Manager116Oracle MySQL95Oracle Financial Services Applications86Oracle Autonomous Health Framework72Oracle Application Testing Suite73Oracle Database Server64Oracle JD Edwards62Oracle Java SE54Oracle Retail Applications55Oracle Essbase43Oracle Food and Beverage Applications22Oracle Construction and Engineering11Oracle Hospitality Applications11SolutionPatches for all affected products are available in the August 2026 advisory.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter so that all matching plugin coverage appears as it is released.Get more informationOracle Critical Security Patch Update Advisory – August 2026Oracle August 2026 Critical Security Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
    by Research Special Operations on August 14, 2026 at 9:36 pm

    Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan’s Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulnerability scanning.The common entry point across all cluster activity is identity and authentication exposure: discoverable federation endpoints, weak credentials, and misconfigured SSO are the conditions autonomous agents exploit at machine speed, and Tenable One can identify this class of risk in customer environments.BackgroundThe Taiwan autonomous AI cyber attack, confirmed by Taiwan’s Ministry of Digital Affairs on Aug. 13, 2026, is the highest-profile event in a broader pattern Tenable’s RSO team has been tracking as an intelligence cluster since July 21, 2026. That cluster now encompasses seven confirmed incidents of autonomous or semi-autonomous AI systems deployed for offensive cyber operations or escaping containment boundaries, spanning November 2025 through August 2026.The Taiwan campaign is the anchor finding, but it is not the whole story. In late July, Palo Alto Networks’ Unit 42 independently documented a separate Chinese-speaking individual operator using the same underlying AI agent framework for autonomous vulnerability scanning. Before either of those events became public, the RSO team was already tracking JADEPUFFER, the first documented agentic threat actor, which exploited an AI workflow platform for initial access and pivoted to database extortion. Three additional agentic AI exploitation incidents emerged during Q1 and Q2 of 2026. And on the defensive side, a confirmed AI sandbox escape incident involving a frontier model demonstrated that autonomous systems can break containment from the inside, not just be weaponized from the outside.Tenable’s RSO team assesses that these events are not coincidental. They represent two sides of the same exposure condition: autonomous AI systems operating beyond the boundaries their developers intended. This FAQ explains what the cluster contains, what the Taiwan anchor event revealed, and what the cluster reveals about the broader exposure condition.FAQWhat happened in the Taiwan AI cyber attack?Between July 1 and July 4, 2026, a suspected China-linked operator ran a four-day intrusion campaign against Taiwanese government infrastructure across 12 distinct attack waves. Starting from a single government portal, autonomous AI agents mapped 21 connected systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records. The operation then expanded beyond its initial foothold to reach Taiwan’s national nuclear safety agency, seven energy companies, government IT supply chain vendors, and a government email system.Dream Security’s chief strategy officer, Amir Becker, a former member of Israel’s Unit 8200, characterized the level of autonomy demonstrated as unprecedented against a government target, according to SecurityAffairs reporting. Taiwan’s Ministry of Digital Affairs confirmed the attack on Aug. 13, 2026, but did not publicly attribute it to a specific state.How did the AI agents conduct the attack autonomously?The operator assembled a multi-agent framework from two open-source AI agent projects, Hermes Agent and OpenClaw, and added Bayesian decision engines capable of coordinating up to eight parallel sub-agents per attack wave. Rather than following a fixed script, the agents scraped the government portal’s publicly accessible authentication metadata: the federated sign-on endpoints, service identifiers, and identity-provider configuration that interconnected web applications routinely expose, then used what they found to independently discover and map the 21 connected systems behind it. In what Dream Security described as a fully autonomous decision, the agents followed a URL from the portal’s JavaScript bundles to a GitBook documentation site hosting the national SSO integration guide, scraped the documentation using GitBook’s built-in content features, and downloaded two SDK integration projects. Dream’s analysis notes that while the agents ran automated code review on the SDK samples, none of those findings produced confirmed exploits. The actual breaches came from server-side flaws discoverable through standard black-box testing.To acquire credentials, the agents generated password variations based on employee identifiers and automatically solved CAPTCHA challenges through optical character recognition, compromising 85 accounts without a human operator manually testing each one. The agents also bypassed their own AI safety guardrails by reframing the offensive operation as “authorized penetration testing,” a novel prompt-based technique with no current mapping in the MITRE ATT&CK framework. Throughout the operation, the agents pulled exploitation techniques from public vulnerability databases and GitHub in real time rather than relying on a pre-loaded set of exploits, a pattern Tenable’s RSO team assesses as genuine adaptive behavior rather than simple scripted branching.Did the attackers exploit a specific vulnerability or zero-day?No single classifiable Common Vulnerabilities and Exposures (CVE) entry drove this campaign. Instead, the AI agents dynamically identified and abused misconfigurations, exposed administrative interfaces, and weak credentials already present in the target environment, sourcing exploitation techniques from public databases as they went. Tenable’s RSO team regards this absence as analytically significant: it demonstrates an attack category that a purely CVE-centric defensive model cannot fully address, because the exposure is the target’s entire discoverable attack surface rather than one known vulnerability.Who was behind the attack?Dream Security’s linguistic analysis of the recovered 160MB archive found that internal operator communications were in Simplified Chinese while the exfiltrated government data was in Traditional Chinese. The targeting sequence (government portal, then nuclear safety agency, then energy sector) also aligns with previously documented Chinese strategic intelligence collection priorities against Taiwan.Attribution currently rests on a single primary source. Dream Security is the sole entity that has published technical and linguistic analysis of the archive, and no second vendor has yet corroborated a link to a specific Chinese state entity. Tenable’s RSO team evaluated three competing attribution hypotheses (state-sponsored, state-adjacent contractor, and false flag) and assesses a state-adjacent contractor or patriotic hacker origin as the leading explanation, with state sponsorship as a close runner-up that cannot be excluded.What is the connection to the Unit 42 findings on knaithe/KnYuan?On July 30, 2026, roughly two weeks before the Taiwan campaign became public, Unit 42 published research on a separate Chinese-speaking individual operator tracked as knaithe (also known as KnYuan), assessed with moderate confidence as operating out of Zhuhai, China. Unit 42 discovered the actor after a misconfigured Hermes Agent instance accidentally exposed the actor’s full operational workspace. Unit 42’s report details the exposed contents: tool configurations, API credentials, exploit scripts, target lists, and session logs from autonomous exploitation runs.Knaithe/KnYuan used Hermes Agent paired with the DeepSeek reasoning model to run autonomous vulnerability-scanning campaigns against Langflow and n8n instances, and separately achieved confirmed data exfiltration from three Citrix NetScaler targets and command execution on 11 Marimo Notebook endpoints through manual exploitation. The actor has no known connection to the Taiwan operator, but the two cases share the same underlying framework and demonstrate that autonomous AI offensive capability is not confined to a single well-resourced group.An individual operator, working alone, independently built comparable tooling, evidence the RSO team views as confirmation that the barrier to entry for this class of attack is collapsing.What is the broader agentic AI threat cluster?The Taiwan campaign is the most visible event, but Tenable’s RSO team is tracking it as one node in a cluster of seven confirmed incidents. The cluster includes three categories of activity.First, offensive weaponization: the Taiwan campaign operator, the knaithe/KnYuan autonomous scanning operation, and JADEPUFFER, the first documented agentic threat actor tracked by the RSO team, which demonstrated agentic AI capability by exploiting Langflow and pivoting to database extortion before either the Taiwan or Unit 42 reports were published. Security vendors documented three additional early-stage agentic exploitation incidents during Q1 and Q2 of 2026.Second, defensive AI escape: a confirmed sandbox escape by a frontier AI model during legitimate safety testing demonstrated that advanced AI systems can independently breach their containment boundaries without any adversary involvement. Other AI laboratories have reported similar incidents, reinforcing the pattern.The RSO team treats these as a single analytical cluster because they share the same root exposure condition: autonomous AI systems acting beyond the boundaries their operators intended. Whether the system was weaponized by an attacker or broke out during legitimate use, the downstream risk to organizations is the same, systems they assumed were controlled were not. This is why the RSO team classifies the open-source AI agent framework weaponization pattern and the broader AI governance gap as distinct exposure conditions tracked under the same cluster umbrella.What makes this different from previous AI-assisted cyber attacks?The individual Taiwan campaign is significant on its own terms, but the cluster pattern is what changes how organizations need to think about risk. Earlier AI-assisted intrusions used AI to accelerate a specific step, such as writing phishing content or triaging scan output, while a human operator directed the overall operation. The Taiwan campaign compressed reconnaissance, credential attacks, and lateral expansion into a continuous, largely self-directed sequence: the agents chose which systems to map, which techniques to pull from public sources, and when to expand into new sectors, all without step-by-step human direction. Kevin Surace, CEO of TokenCore, described the operation as “near-autonomous rather than completely independent,” adding that “humans still selected the targets, defined the objectives, assembled the framework, and reportedly persuaded the underlying model that the operation was an authorized security test.” Tenable’s RSO team adopts the same “near-autonomous” framing.What elevates this beyond a single incident is the convergence the cluster reveals. Two unrelated actors independently adopted the same framework. A third actor (JADEPUFFER) demonstrated agentic capability through a different operational pattern. AI systems escaped containment without adversary involvement. The barrier to entry collapsed far enough that a solo operator in Zhuhai built comparable tooling to what was used against a national government. As Trey Ford observed, this is “not the first AI-driven government attack,” but rather “the first one we’ve heard about.” The cluster data suggests he is right.What does the tradecraft analysis reveal about how these attacks actually work?Tenable’s RSO team conducted structured tradecraft profiling across all three actors and the anchor campaign to understand how agentic AI attacks compare to conventional intrusions at the operational level. Four findings stand out.First, agentic AI tradecraft is additive, not transformative. The innovation in this cluster is concentrated in one dimension: the use of AI agents as the execution engine. Everything else, the command-and-control infrastructure, the initial access vectors, the operational security practices, remains at commodity levels. The Taiwan operator’s AI agents autonomously mapped 21 systems and compromised 85 accounts, but the underlying techniques they used (credential brute force against weak passwords, abuse of discoverable OAuth and Keycloak metadata, exploitation of publicly known vulnerabilities) are familiar. What changed is the speed, parallelism, and self-direction with which those techniques were applied. For defenders, this means the kill chain itself has not fundamentally changed. What has changed is the tempo at which an attacker can execute it.Second, the convergence across unrelated actors is not coincidental, and the tradecraft data confirms it. When the RSO team compared the operational profiles of the Taiwan operator, knaithe/KnYuan, and JADEPUFFER, all three produced strikingly similar capability levels despite having no organizational relationship, shared training, or common infrastructure. The similarity is structural: the same freely available open-source tools (Hermes Agent, OpenClaw, DeepSeek) impose a common operational template on anyone who uses them. This is the clearest evidence that the barrier to autonomous AI offensive capability has collapsed. The tools define the tradecraft, and the tools are available to everyone.Third, these actors are not living off the land. The RSO team estimates the substantial majority of the observed tradecraft in this cluster was AI-agent-driven rather than reliant on the target environment’s native tools. The small portion that did leverage target infrastructure involved abusing the inherent discoverability of federated authentication systems (OAuth discovery endpoints, OpenID Connect metadata, Keycloak realm configurations). This matters for detection strategy: catching agentic AI intrusions requires a different detection model than living-off-the-land indicators that flag conventional APT activity. The detection focus can be on execution-layer anomalies, specifically the behavioral signatures of AI-driven reconnaissance, automated credential campaigns, and parallel multi-target scanning.Fourth, the speed of adaptation compresses the defender’s window to near zero. In the JADEPUFFER campaign documented by Sysdig, an AI agent diagnosed a failed credential insertion, identified the cause as a missing runtime dependency in the execution environment, and issued a corrective multi-step payload within 31 seconds. Traditional incident response timelines assume minutes to hours between attacker actions. Agentic AI eliminates that breathing room. Every exposed credential, every misconfigured authentication endpoint, every unpatched service will be found and will be exploited at machine speed. The window between exposure and compromise is collapsing, which makes foundational cyber hygiene (patching, hardening, reducing the discoverable attack surface) more urgent than it has ever been, not less.How does this affect organizations deploying AI agents?The attack surface the Taiwan agents exploited is not specific to Taiwanese government infrastructure. Any organization running interconnected web applications with centralized authentication (OAuth or OpenID Connect federation, SAML providers, or Keycloak deployments) exposes the same category of discoverable metadata the Taiwan operator’s agents used to map 21 systems from a single entry point. The methodology is geography-agnostic: the agents require only one foothold and self-discover everything else.The Taiwan agents also autonomously discovered and scraped a GitBook documentation portal hosting the national SSO integration guide, using GitBook’s built-in content features to download SDK integration samples. Organizations that host developer documentation, API guides, or integration resources on publicly accessible platforms treat that content as part of the discoverable attack surface: autonomous agents will find it.Separately, organizations that deploy their own AI agents face an additional governance exposure. Industry survey data from Kiteworks indicates that 63% of organizations cannot enforce purpose limitations on the AI agents they deploy, 60% cannot quickly terminate a misbehaving agent, and 55% cannot isolate AI systems from broader network access. The Cybersecurity and Infrastructure Security Agency (CISA) and Five Eyes partners published joint guidance titled “Careful Adoption of Agentic AI Services” in May 2026, identifying privilege escalation, design and configuration failures, behavioral misalignment, structural brittleness, and accountability gaps as the core risk categories. These are two distinct exposure categories: being targeted by AI agents and governing your own, but both require action now.What can organizations do to protect themselves?This campaign is a forcing function to address two distinct exposure categories. First, the identity and authentication weaknesses the Taiwan attacker actually exploited (exposed discovery endpoints, weak credentials, and misconfigured federation) exist in most enterprise environments today and are exactly the kind of foothold agentic AI will find at machine speed. Second, organizations deploying their own AI agents face the governance gaps Kiteworks documented: if you cannot enforce purpose limitations or terminate a misbehaving agent, you share the same structural vulnerability from the inside. Neither category has a single patch. Both require architectural and operational changes.Audit public-facing authentication surfaces for information disclosure. Review OAuth, OpenID Connect discovery endpoints, and Keycloak realm configurations for unnecessary public exposure, since the Taiwan operator’s entire ecosystem map originated from data these interfaces exposed voluntarily. The Taiwan agents autonomously discovered a GitBook documentation portal hosting the national SSO integration guide, scraped it, and downloaded SDK integration samples, all from a single URL embedded in the portal’s JavaScript. Publicly accessible developer documentation, integration guides, and SDK samples are part of the discoverable attack surface that agentic AI will find.Deploy behavioral detection for automated reconnaissance and credential attacks, including quick sequential API enumeration, mass credential testing paired with CAPTCHA solve-and-retry patterns, and parallel scanning of multiple connected systems within minutes of an initial compromise. Indicator-based detection alone is insufficient because autonomous AI agent traffic closely resembles legitimate security testing.Reduce the discoverable attack surface. The Taiwan agents built their entire operation from information the target environment volunteered: authentication metadata, API endpoints, developer documentation, and SDK integration guides hosted on publicly accessible platforms. Audit what internet-facing applications expose through JavaScript bundles, discovery endpoints, documentation portals, and integration resources. If it helps a legitimate developer integrate, it helps an autonomous agent map your environment.Close the purpose-limitation and kill-switch gap identified by Kiteworks. Organizations that cannot quickly terminate a misbehaving AI agent or restrict what it is authorized to do are exposed to the same category of risk the Taiwan attack demonstrated, independent of any single vulnerability.Organizations running Citrix NetScaler, Marimo Notebook, Langflow, n8n, Apache Tomcat, PAN-OS, or Windows IKE VPN, the platforms targeted in the related knaithe/KnYuan campaign, can check patch status via the CVE links in the Product Coverage section below. Manual exploitation following autonomous reconnaissance has already produced confirmed data exfiltration and command execution against unpatched instances of some of these products.Has Tenable released any product coverage for these threats?Tenable customers can use the Tenable One Exposure Management Platform to assess their exposure to this threat cluster across three dimensions. Tenable One Attack Surface Management helps identify internet-facing authentication surfaces, OAuth and OpenID Connect discovery endpoints, and exposed AI agent framework instances before an adversary finds them. Tenable One Identity Exposure helps organizations surface the excessive privileges, weak credential patterns, and misconfigured single sign-on integrations that AI agents in this campaign exploited without needing a single CVE. Tenable One Vulnerability Management provides coverage for the known vulnerabilities exploited in the related knaithe/KnYuan campaign, including:CVE-2026-33017 (Langflow)CVE-2026-3055 (Citrix NetScaler)CVE-2026-39987 (Marimo Notebook)CVE-2026-34486 (Apache Tomcat)CVE-2026-21858 (n8n)CVE-2025-68613 (n8n)CVE-2026-0300 (PAN-OS)CVE-2026-33824 (Windows IKE VPN)These links will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.JADEPUFFER, a separate actor in the same cluster, exploited an earlier Langflow vulnerability (CVE-2025-3248) in its database extortion campaign. Tenable plugin coverage for that CVE is also available.During the autonomous SDK code review phase, the agents also identified a Cross-Site Request Forgery weakness in the portal’s SSO integration. CSRF was not among the confirmed breach vectors in this campaign (the actual compromises came from server-side authentication flaws), but Tenable One Web App Scanning can identify this class of vulnerability in customer-facing portals with federated authentication:Cross-Site Request ForgeryCross-Site Request Forgery Token Validation BypassWhat does this mean for the future of cybersecurity?Tenable’s RSO team is actively monitoring seven indicators tied to this cluster. The four forecasts in our internal assessment deserve public summary.First, framework proliferation: the RSO team assesses with moderate confidence that additional actors across multiple capability tiers will adopt autonomous AI attack methodologies within the next six to 12 months. Two distinct actors already built comparable capability independently, and the open-source tools they used remain freely available under permissive licenses.Second, target expansion: the methodology is geography-agnostic. The AI agents require only a single entry point and self-discover everything else. The RSO team assesses that the same or similar frameworks will likely appear against non-Taiwan targets within three to six months, a timeline the knaithe/KnYuan discovery (which predated the Taiwan disclosure) already suggests is conservative.Third, regulatory acceleration: the Taiwan incident provides concrete evidence for regulatory bodies that were already moving on agentic AI governance. The RSO team assesses that CISA or an equivalent Five Eyes agency will likely issue additional agentic AI guidance within three months, building on the joint guidance published in May 2026.Fourth, defensive AI containment failures will continue. The sandbox escape incident tracked as FIND-020 and similar events at other AI laboratories are not anomalies. As AI models grow more capable, organizations face a dual-axis threat: offensive weaponization by adversaries from the outside and defensive containment failure from the inside. Both vectors converge on the same exposure: autonomous systems operating beyond the boundaries organizations assume they control.The RSO team will continue to track this cluster and publish updates as monitoring indicators are triggered. Organizations that treat the Taiwan event as an isolated incident rather than a pattern will find themselves behind the curve when the next data point arrives.Get more informationTenable One Exposure Management PlatformCISA and Five Eyes – “Careful Adoption of Agentic AI Services” (May 2026)Unit 42 – “Chinese-Speaking Threat Actor Harnesses AI Models” (July 30, 2026)Dream Security – “Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia” (Aug. 12, 2026)Sysdig TRT – “JADEPUFFER: Agentic Ransomware for Automated Database Extortion” (July 1, 2026)Taiwan Ministry of Digital Affairs – official confirmation (English Translation) (Aug. 13, 2026)Tenable Vulnerability Watch – authoritative vulnerability classificationJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One Exposure Management Platform, the exposure management platform for the modern attack surface.

  • Microsoft’s August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)
    by Research Special Operations on August 11, 2026 at 2:04 pm

    42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Services (AD CS)Application Information ServicesAzure Active DirectoryAzure CycleCloudAzure Monitor AgentAzure Storage ExplorerCapability Access Management Service (camsvc)Desktop Window ManagerDynamics Business CentralGitHub Copilot and Visual Studio CodeMicrosoft Azure Attestation service and Device Health Attestation ServiceMicrosoft COM for WindowsMicrosoft Defender for EndpointMicrosoft Digest AuthenticationMicrosoft Dynamics 365 (on-premises)Microsoft Entra Connect SyncMicrosoft Exchange ServerMicrosoft High Performance Computing (HPC) PackMicrosoft Identity ServicesMicrosoft Local Security Authority Server (lsasrv)Microsoft OfficeMicrosoft Office AccessMicrosoft Office ExcelMicrosoft Office Graphics ComponentMicrosoft Office OutlookMicrosoft Office PowerPointMicrosoft Office SharePointMicrosoft Office WordMicrosoft OneDriveMicrosoft PowerShellMicrosoft PowerShell CoreMicrosoft QUICMicrosoft Remote Registry ServiceMicrosoft Teams MobileMicrosoft Teams for AndroidMicrosoft Windows Codecs LibraryMicrosoft Windows Media FoundationMicrosoft Windows Search ComponentPower BIRPC RuntimeReliable Multicast Transport Driver (RMCAST)Remote Desktop ClientUser-Mode Power Service (UMPS)Virtual Hard Disk (VHD) Miniport DriverVisual Studio CodeVisual Studio Code – Python extensionVisual Studio Code CoPilot Chat ExtensionWindows Accessibility Infrastructure (ATBroker.exe)Windows Active DirectoryWindows Ancillary Function Driver for WinSockWindows AutopilotWindows Backup EngineWindows Bind Filter DriverWindows Cloud Files Mini Filter DriverWindows Common Log File System DriverWindows Container Isolation FS Filter Driver (unionfs.sys)Windows Cross Device ServiceWindows DHCP ClientWindows DHCP ServerWindows DNSWindows DWM Core LibraryWindows Defender Firewall ServiceWindows Deployment ServicesWindows Device Association ServiceWindows Display Enhancement ServiceWindows Encrypting File System (EFS)Windows Event Logging ServiceWindows GDIWindows GDI+Windows Graphics KernelWindows HTTP Protocol StackWindows HTTP.sysWindows HelloWindows Hyper-VWindows Imaging ComponentWindows InstallerWindows KerberosWindows KernelWindows Key GuardWindows LDAP – Lightweight Directory Access ProtocolWindows LUAFVWindows License ManagerWindows MIDI Service ModuleWindows Management InstrumentationWindows Management ServicesWindows Message QueuingWindows Modern Device Management (MDM)Windows NTFSWindows Narrator BrailleWindows Network Address Translation (NAT)Windows Network Connection BrokerWindows Network File SystemWindows Package ManagerWindows Program Compatibility Assistant ServiceWindows Projected File SystemWindows Push NotificationsWindows RPC APIWindows Remote Access APIWindows Remote Access Connection ManagerWindows Remote Desktop ServicesWindows Remote HelpWindows Remote Help DefenseWindows Routing and Remote Access Service (RRAS)Windows SMB ClientWindows SMB ServerWindows SchannelWindows Secure Socket Tunneling Protocol (SSTP)Windows Sensor Data ServiceWindows ShellWindows StorageWindows Storage Port DriverWindows TCP/IPWindows Telephony ServiceWindows USB DriverWindows Universal Disk Format File System Driver (UDFS)Windows User Profile ServiceWindows Win32KWindows Wired AutoConfig ServiceWindows Work Folder ServiceWindows iSCSI Target ServiceWinlogonElevation of Privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%.ImportantCVE-2026-68820 | Windows Ancillary Function Driver for WinSock elevation of privilege vulnerabilityCVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.Two additional EoP vulnerabilities affecting this driver were patched this month. CVE-2026-61348 and CVE-2026-70307 also received CVSSv3 scores of 7.0, however no exploitation has been reported for these flaws. Both were assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index.Prior zero-days in this driver include CVE-2025-32709 in May 2025, CVE-2025-21418 in February 2025, and CVE-2024-38193 in August 2024.ImportantCVE-2026-62832 | Windows User Profile Service elevation of privilege vulnerabilityCVE-2026-62832 is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.”Historically, the Windows User Profile Service has received four total CVEs since January 2022. Prior zero-days in this family include CVE-2022-21919 in January 2022 and CVE-2022-26904 in April 2022.ImportantCVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerabilityCVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.”CriticalCVE-2026-62893 | Windows Deployment Services TFTP Server remote code execution vulnerabilityCVE-2026-62893 is a remote code execution vulnerability affecting Windows Deployment Services Trivial File Transfer Protocol (TFTP) Server. It received a CVSSv3 score of 9.8 and is rated as critical. It was assessed as “Exploitation More Likely.” Successful exploitation of this flaw could occur when a remote, unauthenticated attacker sends crafted packets to a vulnerable service, resulting in code execution. It was reported to Microsoft by Nikolai Skliarenko of TrendAI Research.CriticalCVE-2026-62823 | Windows DHCP Server remote code execution vulnerabilityCVE-2026-62823 is a remote code execution vulnerability affecting Windows DHCP Server. It received a CVSSv3 score of 8.8 and is rated as critical. It was assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index. Successful exploitation would allow a remote, unauthenticated attacker to execute code over an adjacent network by exploiting a heap-based buffer overflow flaw using a crafted packet.13 additional Windows DHCP server vulnerabilities were patched this month, however these flaws were only rated as important. The flaws include eight information disclosure vulnerabilities with CVSSv3 scores of 6.5 (CVE-2026-62714, CVE-2026-62715, CVE-2026-62716, CVE-2026-62718, CVE-2026-62720, CVE-2026-62742, CVE-2026-62745 and CVE-2026-62814) and five EoP vulnerabilities with CVSSv3 scores of 7.8 (CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807 and CVE-2026-62812).CriticalMultiple CVEs | Microsoft Office SharePoint spoofing, remote code execution, elevation of privilege, information disclosure and tampering vulnerabilitiesThis month’s update includes patches for 29 CVEs affecting Microsoft Office SharePoint. Of the 29 CVEs, three were rated as critical and three were assessed as ‘Exploitation More Likely.’ A breakdown of the CVEs can be found in the table below:CVEDescriptionCVSSv3SeverityExploitability IndexCVE-2026-70306Microsoft Office SharePoint Spoofing9.3ImportantExploitation Less LikelyCVE-2026-62827Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less LikelyCVE-2026-65665Microsoft SharePoint Server Remote Code Execution8.8CriticalExploitation More LikelyCVE-2026-64921Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less LikelyCVE-2026-63514Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-64901Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-65658Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-65663Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-66805Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-66808Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-70321Microsoft SharePoint Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-70324Microsoft SharePoint Elevation of Privilege8.8ImportantExploitation Less LikelyCVE-2026-70326Microsoft SharePoint Server Elevation of Privilege8.8ImportantExploitation Less LikelyCVE-2026-63520Microsoft SharePoint Server Remote Code Execution8.1ImportantExploitation More LikelyCVE-2026-57105Microsoft Office SharePoint Spoofing8.0ImportantExploitation Less LikelyCVE-2026-70355Microsoft SharePoint Server Elevation of Privilege7.3ImportantExploitation More LikelyCVE-2026-58639Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-62837Microsoft SharePoint Server Information Disclosure6.5ImportantExploitation Less LikelyCVE-2026-62839Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-63512Microsoft SharePoint Server Tampering6.5ImportantExploitation Less LikelyCVE-2026-63516Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-65660Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-62829Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-62917Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64897Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64922Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64900Microsoft SharePoint Server Spoofing7.3ImportantN/ACVE-2026-64902Microsoft SharePoint Server Spoofing4.6ImportantN/ACVE-2026-64916Microsoft SharePoint Server Spoofing4.6ImportantExploitation UnlikelyTenable solutionsA list of all the plugins released for Microsoft’s August 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.Get more informationMicrosoft’s August 2026 Security UpdatesTenable plugins for Microsoft August 2026 Patch Tuesday Security UpdatesJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • Coordinated “cyberattack” on U.S. water utilities: What you need to know
    by Research Special Operations on July 28, 2026 at 11:19 pm

    A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable’s Research Special Operations team is monitoring developments and will update this FAQ as new information becomes available from federal agencies, state officials, and independent reporting.Click here to review the change log historyUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.Update August 6: This FAQ has been updated to add publicly confirmed affected states and a named victim, incorporate the FBI’s identification of targeted PLC models and reported operational impacts (pressure loss, flooding), and add additional reference links. The title and introduction have been updated to reflect the nationwide scope of the campaign.Update August 4: This FAQ has been updated to include an ABC News report that says attacks have been reported in at least 12 states.Update August 4: This FAQ has been updated to note that the attacks have affected at least seven states, including Minnesota and Michigan, and to add details of a new CISA sector alert for water and wastewater systems.Key TakeawaysA coordinated cyber attack targeted water and wastewater systems; attribution remains pending a federal investigation, though the timing aligns closely with escalating Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A.The July 22, 2026 update to CISA Advisory AA26-097A expanded the scope of observed PLC exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation, documented project file exfiltration for the first time, and added detection guidance for manipulation of reusable code modules embedded in PLC programs.CVE-2021-22681 (CVSS 9.8), a critical authentication bypass in Rockwell Automation Logix controllers with no available vendor patch, was added to CISA’s Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors.BackgroundTenable’s Research Special Operations (RSO) team has compiled this FAQ in response to the coordinated cyber attack against Minnesota water utilities and the July 22, 2026 update to CISA Advisory AA26-097A.On April 9, 2026, we published a comprehensive FAQ about CyberAv3ngers, the IRGC-linked group at the center of the PLC exploitation activity documented in CISA Advisory AA26-097A. That post covers the group’s history, four-phase capability escalation, IOCONTROL malware, and a full technical breakdown of CVE-2021-22681. This post addresses what has changed since then.FAQWhat happened to water utilities in Minnesota?Between Sunday, July 26, and Monday, July 27, 2026, a coordinated cyber attack disrupted water and wastewater utility operations across more than 30 communities in Minnesota. Four cities publicly disclosed attacks: Braham, Plymouth, South St. Paul, and Maple Plain. Minnesota IT Services described the incident as a coordinated cyber attack targeting technology at community water systems across the state.In Braham, a community of approximately 1,700 people, the attack disabled computerized operating controls and temporarily shut down the city’s well and water treatment plant. Public works crews restored the plant within approximately two hours. In Plymouth (population approximately 80,000), the city’s IT division disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the attack and prevent retargeting while equipment was reconfigured. Crews continued operating through manual procedures. South St. Paul reported that some automated water utility controls were affected, while Maple Plain declared a local state of emergency to expand its response capabilities.In all confirmed Minnesota cases, state officials said drinking water quality was not affected and no boil-water advisories were issued in the state. Separately, CISA reported on July 30 that the broader campaign has led to boil-water notices and extended manual operations at utilities.Were any other states affected besides Minnesota?Yes, at least 12 states have reportedly been affected according to an ABC News report published on August 4. On August 6, CBS News independently confirmed the 12-state scope.The Federal Bureau of Investigation (FBI) and U.S. Environmental Protection Agency (EPA) stated in their July 30 joint public service announcement (Alert: I-073026-PSA) that since July 27, 2026, water and wastewater utilities in at least seven states had reported incidents, and that some of that activity had “degraded water operations.” The FBI stated that reported operational effects have included pressure loss and flooding, and identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as the targeted devices. The PSA does not attribute the activity to any specific actor, referring only to “malicious cyber actors.”In addition to Minnesota, four states have been publicly identified. Michigan’s Department of Environment, Great Lakes, and Energy (EGLE) confirmed on August 1 that nine municipal water systems reported activity consistent with the federal warnings. South Dakota has been identified as an affected state in CBS News reporting; specific facilities have not been publicly named. In Georgia, cyber activity caused a pressure drop at the Clayton County Water Authority, prompting a boil-water advisory for the utility’s 300,000 customers in the Atlanta area. The authority restored service within hours. Columbus Water Works confirmed on August 5 that it had also detected a cyber intrusion; drinking water was not affected. New Jersey has also been identified as an affected state in CBS News reporting. The remaining states have not been publicly named by federal agencies or confirmed by state officials.The following table summarizes publicly confirmed affected entities to date:StateFacility / SystemDate ConfirmedImpact / StatusSourceMinnesotaMore than 30 communitiesJuly 27, 2026Disabled controls, pressure loss, temporary shutdowns; manual operations; restored within hours; no drinking water impactMNIT; The Hacker NewsMichiganNine unnamed systemsAugust 1, 2026Activity consistent with federal warnings; no public health impactMI EGLEGeorgiaClayton County Water AuthorityJuly 27, 2026Pressure drop; boil-water advisory (300,000 customers); restored within hoursCBS NewsGeorgiaColumbus Water WorksAugust 5, 2026 (confirmed); July 27 (incident)Cyber intrusion detected; drinking water not affectedWSB-TV AtlantaNew JerseyNot publicly namedAugust 6, 2026 (reported)Not disclosedCBS NewsSouth DakotaNot publicly namedAugust 6, 2026 (reported)Not disclosedCBS NewsWho is behind the attack?Federal and state officials have not publicly attributed the Minnesota attacks to any specific actor. However, the operational pattern is consistent with the CyberAv3ngers threat ecosystem, a state-directed group the U.S. government has formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command.In February 2024, the U.S. Treasury Department sanctioned six IRGC-CEC officials for directing CyberAv3ngers operations, and the State Department offered up to $10 million for information on the group through the Rewards for Justice program. The group has been active since at least 2020; the security community tracks it under multiple designations, including Storm-0784 (Microsoft), Bauxite (Dragos), Hydro Kitten, UNC5691 (Mandiant), and MITRE ATT&CK group ID G1027. In April 2026, Tenable Research Special Operations published a comprehensive FAQ on CyberAv3ngers detailing the group’s history, capabilities, and targeting profile.The timing of the Minnesota attacks is significant. CISA updated Advisory AA26-097A on July 22, just four days before the attacks began, warning that Iranian-affiliated actors had been compromising internet-connected PLCs across U.S. water, energy, and government sectors. The advisory documented confirmed disruptions and financial losses at multiple organizations.What changed in the July 22, 2026 update to CISA Advisory AA26-097A?The original advisory, published April 7, 2026, documented Iranian-affiliated actors exploiting internet-exposed Rockwell Automation/Allen-Bradley PLCs to cause disruptions across the Government Services, Water and Wastewater, and Energy sectors. CISA confirmed disruptions at victim organizations have occurred since at least March 2026. Three significant additions were made in the July 22 update.The advisory expanded its scope to include observed targeting of Schneider Electric and Siemens PLCs alongside Rockwell Automation devices. The update also documented a new exfiltration tactic: using vendor engineering software (Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ TIA Portal) on leased, third-party hosted infrastructure, actors have been observed pulling PLC project files out of victim environments and transferring them to systems under their control. Finally, the update provided detection guidance for manipulation of Add-On Instructions (AOIs), reusable code modules embedded in PLC programs. The FBI observed that at one victim, a malicious project file retained normal downstream ladder logic while inserting modified AOIs that disabled safety shutdown and alarm systems; actors also manipulated data on HMI and SCADA displays, allowing equipment to operate in unsafe conditions without alerting operators.A new set of indicators of compromise was released alongside the update, covering IP addresses associated with actor activity from September 2025 through July 2026. The advisory directly references observed targeting of Schneider Electric BMX P34/Modicon M340 PLCs and Siemens S7-1200 PLCs, and notes that activity on ports associated with other OT vendor protocols suggests broader opportunistic targeting beyond the named manufacturers.Did CISA issue any new alerts or advisories after the attacks were reported?Yes. On July 30, 2026, CISA published a sector-wide alert urging the Water and Wastewater Systems sector to protect operational technology against ongoing PLC-targeting activity. This alert is distinct from CISA Advisory AA26-097A (last updated July 22). It names no country or group and focuses on immediate mitigations.CISA reported it was observing a significant increase in threat actors targeting programmable logic controllers in the Water and Wastewater Systems sector, and described actors modifying passwords to lock out operators and disconnecting PLCs by changing their IP addresses. That activity led to boil-water notices and extended periods of manual operations at affected utilities.How has CyberAv3ngers evolved over time?CyberAv3ngers has demonstrated a deliberate capability escalation across four documented phases:In Phase One (2020–2022), the group operated as a propaganda persona, claiming responsibility for infrastructure disruptions in Israel that were later assessed as fabricated. DomainTools Investigations demonstrated that several claims reused imagery from earlier data leaks.In Phase Two (October 2023–January 2024), the group compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting default passwords on internet-exposed devices. The Municipal Water Authority of Aliquippa, Pennsylvania, was the highest-profile victim.In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices. OpenAI disclosed in October 2024 that CyberAv3ngers had used ChatGPT to assist with target reconnaissance and code debugging.In Phase Four (March 2026 to present), the group pivoted to exploiting CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers. Actors connected to internet-facing PLCs from foreign hosting providers using the same manufacturer engineering software (Studio 5000 Logix Designer) that legitimate operators use. Once connected, they downloaded and modified controller project files and altered operator display data. The July 22 advisory update expanded the manufacturer scope to include Schneider Electric and Siemens PLCs alongside Rockwell Automation.What vulnerability is being exploited?CISA Advisory AA26-097A does not name specific CVE IDs. The advisory characterizes the access method as exploitation of internet-exposed, misconfigured PLCs through vendor engineering software, rather than identifying a discrete software flaw. The vulnerability most directly associated with the documented exploitation is CVE-2021-22681, identified through external research as the authentication weakness enabling Phase 4 of the Iranian-affiliated PLC exploitation campaign, and added to CISA’s Known Exploited Vulnerabilities catalog in March 2026.Three additional CVEs relevant to the Rockwell Automation ControlLogix platform are included below as defensive context for organizations hardening these environments:CVEDescriptionCVSSv3CVE-2021-22681Authentication bypass in Rockwell Automation Logix controllers via insufficiently protected cryptographic key9.8CVE-2023-3595Remote code execution in Rockwell ControlLogix 1756 communication modules9.8CVE-2024-6242Trusted Slot feature bypass in Rockwell ControlLogix controllers8.4**CVE-2024-6242: CVSS 3.x score of 8.4 is vendor-assigned (Rockwell Automation); NVD assigns a CVSS 4.0 score of 7.3.CVE-2021-22681 is a critical authentication bypass in Rockwell Automation’s Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers. For the full technical breakdown of this vulnerability, see our April 9 FAQ.CVE-2023-3595 affects the 1756 EN2 and EN3 series ControlLogix communication modules. Exploitation via maliciously crafted CIP messages could allow an unauthenticated remote attacker to execute arbitrary code and maintain persistent access, including modifying controller memory. This CVE has not been confirmed as exploited in connection with the AA26-097A campaign; it is included because the affected hardware is central to the ControlLogix platform being targeted.CVE-2024-6242, identified by Claroty Team82, affects the Trusted Slot feature in the Rockwell Automation 1756 ControlLogix chassis. Exploitation allows an attacker already on the chassis to execute CIP commands that bypass Trusted Slot protections, potentially modifying user projects. This CVE has not been confirmed as exploited in connection with the AA26-097A campaign and is included as hardening context for ControlLogix deployments.Was CVE-2021-22681 exploited as a zero-day?No. CVE-2021-22681 was originally disclosed in February 2021 and mitigated at that time. However, in-the-wild exploitation was not confirmed until March 2026, when Rockwell Automation updated its advisory (SD1672) to note active exploitation. The five-year gap between disclosure and confirmed exploitation reflects the persistent challenge of patching OT environments, where operational continuity often takes precedence over security updates.Is there a patch available?No. Rockwell Automation has stated that CVE-2021-22681 cannot be fully addressed with a software patch. There is no update to deploy and no patch cycle to wait for. Rockwell directs customers to apply defense-in-depth mitigations instead, including network segmentation, engineering workstation isolation, CIP (Common Industrial Protocol) Security enablement, and physical mode switch hardening.This is a critical operational detail for vulnerability management teams: organizations that rely on patch-based remediation workflows will not resolve this vulnerability through their standard processes. Architectural controls are the only available remediation path.Are there indicators of compromise?Yes. CISA released an updated STIX-formatted indicator bundle alongside the July 22 advisory revision covering IP addresses associated with Iranian-affiliated actor activity targeting PLCs from September 2025 through July 2026. Historical indicators from the April 7 advisory also remain valid. Both sets are available for download at the AA26-097A advisory page.Defenders can monitor for inbound traffic on ports 44818 (EtherNet/IP), 2222 (SSH), 102 (S7comm), 502 (Modbus), and port 22 on OT-connected modems, particularly from foreign-hosted IP ranges. CISA noted that in at least one incident, actors deployed Dropbear SSH on victim modems to maintain persistent remote access over port 22. Unexpected connections to PLC management interfaces from unregistered workstations or overseas infrastructure warrant investigation, as do unauthorized PLC project file modifications or AOI changes occurring outside documented maintenance windows.Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?Yes. Tenable Research has classified CVE-2021-22681 as part of Vulnerability Watch. We are actively monitoring exploitation activity, tracking new developments, and will update this post as additional information becomes available.How large is the exposure surface?Censys analysis conducted in April 2026 identified 5,219 internet-exposed hosts globally that responded to industrial protocols and self-identified as Rockwell Automation/Allen-Bradley devices. The United States accounts for 74.6% of global exposure, with 3,891 hosts. A disproportionate share of these devices operate on cellular carrier networks, consistent with field-deployed PLCs connected via cellular modems, which is precisely the attack vector described in the Plymouth, Minnesota, incident.The systemic nature of this exposure extends beyond Rockwell devices. The EPA warned in 2024 that more than 70% of U.S. water systems were failing to comply with a provision of a 2018 law requiring them to develop or update risk assessments and emergency response plans. An audit of 1,000 water systems serving 193 million people found 97 systems with critical or high-risk vulnerabilities. The United States has between 150,000 and 170,000 water systems, many of them small, rural, and with limited cybersecurity resources.Why do small water utilities keep getting targeted?CyberAv3ngers has repeatedly compromised small water utilities and municipal facilities, and the pattern is structural rather than coincidental. Many of these organizations manage their OT environments with consumer-grade remote access tools such as TeamViewer or AnyDesk, or by exposing PLC management interfaces directly to the public internet. These access methods bypass enterprise security controls entirely, creating an attack surface that is invisible to conventional security monitoring.The problem is compounded by inadequate network segmentation between IT and OT environments. When a PLC is reachable from the same network as email servers and employee workstations, the blast radius of any compromise extends well beyond the initial entry point. Small utilities typically lack dedicated OT security staff and operate under constrained budgets that make comprehensive security architecture difficult to implement.Is there a broader geopolitical context?Yes. The United States and Iran have been in active armed conflict since Operation Epic Fury commenced on February 28, 2026. Iranian cyber operations have escalated in parallel with kinetic hostilities, with confirmed targeting of U.S. critical infrastructure. In June 2026, U.S. strikes along Iran’s southern coast destroyed a water facility near the Strait of Hormuz, cutting water access to more than 20,000 Iranians. The following day, the Handala threat group (linked to Iran’s Ministry of Intelligence and Security) claimed it had breached water utility systems in several California cities as a retaliatory warning.CyberAv3ngers’ exploitation techniques have also proliferated to 60+ affiliated hacktivist groups that have adopted its playbook, coordinated through an “Electronic Operations Room” established at the start of the conflict. These proxy groups are replicating CyberAv3ngers’ ICS exploitation techniques, creating a distributed threat that persists even if the core CyberAv3ngers group is degraded. This proliferation increases the risk of unintended physical consequences from operators who may lack the discipline or understanding to control the effects of PLC manipulation.What should organizations do?Organizations operating internet-exposed PLCs, particularly Rockwell Automation, Schneider Electric, and Siemens devices, can take the following steps:Disconnect PLCs from direct internet exposure. Any internet-accessible Rockwell Logix controller is exploitable via CVE-2021-22681 without authentication, and there is no vendor patch. Separately, the FBI/EPA public service announcement identifies MicroLogix 1100 and 1400 series PLCs as specifically targeted in this campaign via a different method: actors remotely access internet-facing MicroLogix devices and change their IP addresses and passwords, resulting in loss of monitoring and control. These devices should also be removed from direct internet exposure. If remote access is operationally necessary, deploy a secure gateway with multifactor authentication. This is the single highest-impact remediation action.Set physical mode switches to “Run.” This prevents remote modification of PLC logic and configurations, blocking the primary impact technique documented in CISA Advisory AA26-097A.Ingest IOCs from the updated CISA Advisory AA26-097A. Download the STIX-formatted indicators of compromise from the July 22, 2026, advisory update and deploy them in SIEM, IDS, and firewall platforms. Monitor for traffic on ports 44818, 2222, 102, 22, and 502 from overseas hosting providers.Implement IT/OT network segmentation. Isolate engineering workstations running Studio 5000 Logix Designer, EcoStruxure Control Expert, and TIA Portal from untrusted network segments. Deploy allowlisting so only authorized workstations can communicate with controllers.Audit cellular OT connections. The Plymouth attack specifically targeted cellular-connected infrastructure. Verify that all cellular-connected PLCs are behind gateway firewalls with logging. Replace consumer cellular modems with industrial cellular gateways supporting VPN tunnels and multifactor authentication.Back up all PLC logic and configurations offline. Store backups on secured physical media and test restore procedures. CyberAv3ngers’ documented TTPs include PLC project file theft and ladder logic manipulation, making offline backups the last-resort recovery mechanism.Has Tenable released any product coverage for these vulnerabilities?A Tenable plugin is available for CVE-2021-22681, last updated June 2026. Tenable One OT Exposure detects this vulnerability in Rockwell Automation Logix controller environments. Tenable customers with Tenable Security Center or Tenable One Vulnerability Management can utilize the OT Recon scan policy to identify Rockwell Automation assets.A list of Tenable plugins for these vulnerabilities can be found on the individual CVE pages as they’re released:CVE-2021-22681CVE-2023-3595CVE-2024-6242This link will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.Tenable customers can use Tenable One Exposure Management Platform to identify affected Rockwell Automation assets in their environment and prioritize remediation based on the active exploitation context documented in this post. Tenable One OT Exposure provides specialized visibility into industrial control system environments, including internet-exposed PLC detection and vulnerability assessment.Get more informationFBI/EPA Public Service Announcement: Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing PLCs (July 30, 2026)CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs (July 30, 2026)CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure (Updated July 22, 2026)Minnesota IT Services: MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructureStateScoop: Coordinated cyberattack disrupts water utilities in 30+ Minnesota communitiesCyberAv3ngers: FAQ About Iran-Linked Threat Group Targeting Critical InfrastructureCISA Advisory AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors (Updated December 2024)Rewards for Justice: CyberAv3ngersOperation Epic Fury: Potential Iranian Cyber Counteroffensive OperationsCyber Retaliation: Analyzing Iranian Cyber Activity Following Operation Epic FuryOperation Epic Fury: Why exposure data changes everything about Iran’s cyber-kinetic campaignJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
    by Research Special Operations on July 21, 2026 at 5:07 pm

    Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patchesBackgroundOn July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%.This quarter’s update includes 261 critical patches across 228 CVEs.SeverityIssues PatchedCVEsCritical261228High763613Medium358332Low6762Total14491235AnalysisThis quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches.A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite41045Oracle Fusion Middleware355219Oracle Communications168122Oracle PeopleSoft8445Oracle MySQL549Oracle Siebel CRM4532Oracle Commerce3926Oracle Supply Chain3916Oracle Financial Services Applications3126Oracle GoldenGate279Oracle Enterprise Manager2713Oracle Retail Applications2220Oracle JD Edwards204Oracle Java SE1917Oracle Virtualization160Oracle Database Server156Oracle TimesTen In-Memory Database144Oracle Utilities Applications1410Oracle Construction and Engineering77Oracle Analytics75Oracle Systems60Oracle SQL Developer55Oracle Autonomous Health Framework43Oracle Application Testing Suite44Oracle Food and Beverage Applications44Oracle HealthCare Applications44Oracle APEX32Oracle Hospitality Applications22Oracle Essbase11Oracle Global Lifecycle Management11Oracle NoSQL Database11Oracle Spatial Studio11SolutionCustomers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the July 2026 advisory for full details.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.Get more informationOracle Critical Patch Update Advisory – July 2026Oracle July 2026 Critical Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
    by Satnam Narang on July 20, 2026 at 9:36 am

    An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of the July 17, 2026 disclosure. Patches are available in WordPress 7.0.2 and 6.9.5; WordPress.org has enabled forced automatic updates across affected supported installations. BackgroundTenable’s Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding wp2shell, two vulnerabilities in WordPress Core that can be chained together to achieve pre-authentication remote code execution.FAQWhat is wp2shell?wp2shell is the name given to two vulnerabilities in WordPress Core.When was wp2shell first disclosed?On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com, a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain.What are the vulnerabilities associated with wp2shell?wp2shell is a two-vulnerability exploit chain affecting WordPress Core.CVEDescriptionCVSSv3CVE-2026-63030WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability9.8CVE-2026-60137WordPress Core WP_Query author__not_in SQL Injection Vulnerability5.9CVE-2026-63030 is a REST API batch-route confusion weakness introduced in WordPress 6.9. CVE-2026-60137 is a SQL injection flaw in the author__not_in parameter of WP_Query, present in WordPress 6.8 and later. When chained on WordPress 6.9.0 through 7.0.1, the two flaws allow an unauthenticated attacker to reach the REST API batch endpoint at /wp-json/batch/v1 and achieve remote code execution. CVE-2026-60137 was discovered and disclosed by security researchers TF1T, dtro, and haongo.CVE-2026-60137 also affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection issue. Because CVE-2026-63030 was introduced in WordPress 6.9, the full RCE chain is only achievable on 6.9.x and 7.0.x installations.How severe is the wp2shell vulnerability chain?An anonymous, unauthenticated user can execute the chain against a default WordPress installation with no plugins required. No preconditions exist beyond the default WordPress configuration. Cloudflare notes that the vulnerable code path is reached when “a persistent object cache is not in use.”Note: wp2shell targets WordPress Core itself rather than a plugin or theme. All four prior WordPress-related entries in the CISA Known Exploited Vulnerabilities (KEV) catalog involve plugins, not core. Pre-authentication remote code execution in WordPress Core is uncommon.CVEProductAdded to KEVRansomwareCVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared)April 30, 2026KnownCVE-2020-25213WordPress File Manager PluginNovember 3, 2021UnknownCVE-2020-11738WordPress Snap Creek Duplicator PluginNovember 3, 2021UnknownCVE-2019-9978WordPress Social Warfare PluginNovember 3, 2021UnknownHow widespread are the attacks exploiting wp2shell?WordPress is the most widely deployed content management system in the world. Some hosted installations will receive patches automatically from their hosting providers; many self-managed installations will not.Hexastrike began observing exploitation attempts in honeypots over the weekend following the July 17 disclosure and has since assisted with incident response in several confirmed attacks. Patchstack has also confirmed in-the-wild exploitation. Other researchers have reported seeing active exploitation in the wild. It’s starting. Seeing first signs of wp2shell RCE exploit actually being used in the wild – pic.twitter.com/VkNcCVwcLV— rahul (@rahulgovind517) July 20, 2026 Which threat actors are exploiting wp2shell?As of July 20, 2026, no specific threat actor or group has been publicly attributed to wp2shell exploitation. This post will be updated if attribution becomes available.Is there a proof-of-concept available for wp2shell?Yes. Multiple public proof-of-concept (PoC) exploits appeared on GitHub within hours of the July 17 disclosure. The presence of these PoCs is being attributed to AI-assisted tooling, which makes patch diffing and exploit development easier for both defenders and attackers. Kues confirmed this directly in Searchlight Cyber’s technical blog, stating that “no security researcher could have found and completed this exploit chain in 10 hours without AI.” Seems that wp2shell PoCs are now floating around the internet, so we’ve published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself – https://t.co/iuU0yiYJBT— hashkitten (@hash_kitten) July 20, 2026 Are patches or mitigations available for wp2shell?Yes. Patches were released on July 17, 2026. WordPress.org has enabled forced automatic updates for supported installations running affected versions.WordPress BranchAffected VersionsFixed VersionsApplicable CVE(s)6.8.×6.8.0 – 6.8.56.8.6CVE-2026-601376.9.×6.9.0 – 6.9.46.9.5CVE-2026-63030, CVE-2026-601377.0.×7.0.0 – 7.0.17.0.2CVE-2026-63030, CVE-2026-601377.1 beta7.1 beta7.1 beta2CVE-2026-63030, CVE-2026-60137For installations that cannot immediately update, Searchlight Cyber offers three temporary options.Install a plugin that blocks unauthenticated users from accessing the REST APIBlock /wp-json/batch/v1 and ?rest_route=/batch/v1 at the web application firewall (WAF) level; ensure both patterns are coveredDeploy a custom PHP plugin available on wp2shell.com that restricts unauthenticated access to the batch endpoint specificallyAll three are interim measures and are not a substitute for applying the available patches.Cloudflare has deployed WAF rules covering both CVE-2026-63030 and CVE-2026-60137 across all plans, including free accounts, for sites proxied through its platform.Are there any indicators of compromise for wp2shell?As of July 20, 2026, no specific indicators of compromise (IoCs) have been publicly released for wp2shell exploitation. This post will be updated if IoCs become publicly available.Has Tenable Research classified wp2shell as part of Vulnerability Watch?Yes. Tenable Research has classified CVE-2026-63030 and CVE-2026-60137 as part of Vulnerability Watch, and both CVEs have been tagged as a Vulnerability of Interest. We are actively monitoring exploitation activity and tracking new developments. We will update this post as additional information becomes available.Has Tenable released product coverage for wp2shell?A list of Tenable plugins for these vulnerabilities can be found on the individual CVE pages:CVE-2026-63030CVE-2026-60137These links will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.Get more informationSearchlight Cyber: wp2shell Pre-Authentication RCE in WordPress CoreSearchlight Cyber: Technical Analysis of the wp2shell Attack ChainWordPress 7.0.2 Security ReleaseGitHub Advisory: GHSA-ff9f-jf42-662q (CVE-2026-63030)GitHub Advisory: GHSA-fpp7-x2x2-2mjf (CVE-2026-60137)Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
    by Research Special Operations on July 16, 2026 at 12:00 pm

    Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet observed exploited at the time of publication, but Microsoft has flagged CVE-2026-58644 as exploited on July 15.Microsoft released patches for all five vulnerabilities and Microsoft Defender Antivirus detection signatures are available to identify exploitation activity for three of the actively exploited flaws.BackgroundTenable’s Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding active exploitation of Microsoft SharePoint Server vulnerabilities.FAQWhen did CISA issue an alert about SharePoint Server exploitation?On July 14, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an alert confirming active exploitation of three on-premises SharePoint Server vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The alert noted that these flaws had been used to gain unauthorized access to SharePoint deployments across all supported on-premises versions and flagged two additional high-risk vulnerabilities, CVE-2026-55040 and CVE-2026-58644, as not yet exploited but warranting immediate patching. However in an update to the security advisory on July 15, Microsoft confirmed CVE-2026-58644 has been exploited in the wild.What vulnerabilities are covered in this alert?Five Microsoft SharePoint Server vulnerabilities are covered in CISA’s alert: Four with confirmed active exploitation and one newly disclosed high-severity flaw that Microsoft assesses as “Exploitation More Likely” according to Microsoft’s Exploitability Index. All five affect all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016.CVEDescriptionCVSSv3VPRCVE-2026-32201Microsoft SharePoint Server Spoofing Vulnerability6.57.2CVE-2026-45659Microsoft SharePoint Remote Code Execution Vulnerability8.89.4CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege Vulnerability9.8 – NVD5.3 – Microsoft9.5CVE-2026-55040Microsoft SharePoint Server Security Feature Bypass Vulnerability9.17.3CVE-2026-58644Microsoft SharePoint Server Remote Code Execution Vulnerability9.87.9*Please note: Tenable’s Vulnerability Priority Rating (VPR) scores are calculated nightly. This blog post was published on July 16 and reflects VPR at that time.What do the actively exploited vulnerabilities do?CVE-2026-32201 is a spoofing flaw rooted in improper input validation. An unauthenticated remote attacker can exploit it over a network without user interaction.CVE-2026-45659 is a remote code execution (RCE) vulnerability involving deserialization of untrusted data. An authenticated attacker can exploit this flaw in order to execute code on an affected SharePoint server.CVE-2026-56164 is an elevation of privilege vulnerability. An unauthenticated attacker can exploit it remotely to elevate privileges on a SharePoint Server.CVE-2026-58644 is a RCE vulnerability that can be abused by an authenticated attacker with at least Site Owner permissions. Successful exploitation would allow the attacker to achieve code execution by exploiting a deserialization of untrusted data flaw.What post-exploitation activity has been observed?According to CISA, attackers have combined CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 to gain entry to on-premises SharePoint Server instances, then pursued several post-exploitation objectives: extracting IIS machine keys, leveraging deserialization techniques to establish persistence, and deploying malware. CISA notes that stolen machine keys can be used to forge requests enabling further exploitation of the server. The advisory notes that key rotation alone is not a complete remediation step, without first removing any key-harvesting artifacts.What is CVE-2026-55040, the vulnerability that has not yet been exploited?CVE-2026-55040 is a security feature bypass rooted in weak authentication. It was assigned a CVSSv3 score of 9.1 and rated as critical. An unauthenticated attacker can exploit it over the network, without user interaction allowing the attacker to impact both confidentiality and integrity.Both CVE-2026-55040 and CVE-2026-58644 were disclosed on July 14, 2026, as part of Microsoft’s July 2026 Patch Tuesday release. As of July 16, 2026, CVE-2026-55040 has not been observed being exploited in the wild.What is the history of exploitation for Microsoft SharePoint Server?Microsoft SharePoint Server has been a recurring target for threat actors across multiple years. CISA’s Known Exploited Vulnerabilities (KEV) catalog contains 12 SharePoint-related entries, including seven currently known to be used in ransomware campaigns. The table below outlines prior SharePoint CVEs added to the KEV catalog.CVEDate Added to KEVKnown RansomwareTenable CoverageCVE-2026-561642026-07-14UnknownJuly 2026 Patch TuesdayCVE-2026-456592026-07-01Unknown–CVE-2026-322012026-04-14UnknownApril 2026 Patch TuesdayCVE-2026-209632026-03-18Unknown–CVE-2025-497062025-07-22YesJuly 2025 Patch TuesdayCVE-2025-497042025-07-22YesJuly 2025 Patch TuesdayCVE-2025-537702025-07-20YesFAQ BlogCVE-2024-380942024-10-22Yes–CVE-2023-249552024-03-26YesExploit Chain Released for Microsoft SharePoint Server VulnerabilitiesCVE-2023-293572024-01-10YesJune 2023 Patch TuesdayExploit Chain Released for Microsoft SharePoint Server VulnerabilitiesCVE-2019-06042021-11-03YesCritical Microsoft SharePoint Remote Code Execution Flaw Actively ExploitedCVE-2020-11472021-11-03Unknown–Which threat actors are exploiting these SharePoint vulnerabilities?As of July 16, 2026, neither CISA nor Microsoft has attributed the active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 or CVE-2026-58644 to specific threat actors or groups.Is there a proof-of-concept available for any of these vulnerabilities?As of July 16, 2026, no public proofs-of-concept are available for any of the five vulnerabilities covered in this FAQ.Are patches and mitigations available?Microsoft released patches for all five vulnerabilities. The table below lists the fixed build numbers for each affected SharePoint version.CVESharePoint Enterprise Server 2016SharePoint Server 2019SharePoint Server Subscription EditionCVE-2026-3220116.0.5548.100316.0.10417.2011416.0.19725.20210CVE-2026-4565916.0.5552.100216.0.10417.2012816.0.19725.20280CVE-2026-5616416.0.5561.100116.0.10417.2017516.0.19725.20434CVE-2026-5504016.0.5561.100116.0.10417.2017516.0.19725.20434CVE-2026-5864416.0.5556.100516.0.10417.2015316.0.19725.20384The CISA advisory and several of the Microsoft security advisories recommend enabling AMSI integration on SharePoint and IIS worker processes and setting the Request Body Scan mode to Full to allow detection of malicious POST payloads. CISA’s hardening guidance also advises against direct internet exposure of SharePoint Servers and recommends restricting external access to SharePoint Central Administration.Are there indicators of compromise?Yes. CISA and Microsoft have published AMSI and Microsoft Defender Antivirus detection signatures for the three actively exploited vulnerabilities.SignatureTypeScopeExploit:Script/SuspSignoutReqBody.AAMSIRequest body scanning; SharePoint Server Subscription Edition only; Microsoft reports active exploitation attempts have been blockedExploit:Script/ToolPaneAuthBypass.AAMSIRequest header scanning; SharePoint Server 2016, 2019, and Subscription EditionExploit:Script/ToolPaneAuthBypass.CAMSIRCE coverage; SharePoint Server 2016, 2019, and Subscription EditionBackdoor:MSIL/LeakFang.A!dhaMDAVPost-exploitation activity; IIS machine key accessCISA recommends reviewing telemetry for anomalous requests, suspicious SharePoint worker-process activity, webshells and machine-key access activity.Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?Yes. Tenable Research has classified CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 and CVE-2026-58644 as part of Vulnerability Watch. The designation applies to flaws with confirmed in-the-wild exploitation and the potential for widespread impact across affected organizations. We are actively tracking developments related to this activity and will update this post as new information becomes available.Has Tenable released product coverage for these vulnerabilities?A list of Tenable plugins can be found on the individual CVE pages:CVE-2026-32201CVE-2026-45659CVE-2026-56164CVE-2026-55040CVE-2026-58644This link will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.Additionally, Tenable Attack Surface Management customers can identify external-facing assets by leveraging the built-in subscription labeled Microsoft Sharepoint Server – v1.Get more informationCISA: CISA Urges SharePoint Hardening After New ExploitationsTenable: Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

  • CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
    by Scott Caveza on July 15, 2026 at 1:14 pm

    SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall’s Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade SSL VPN gateways which serve as the front door to organizational networks. The SMA series models sit at the edge of the network, internet-facing by design. Because SMA 1000 appliances aggregate remote access credentials and sit directly on the internet, they represent high-value targets for attackers. A compromise at the appliance level can yield administrator credentials, VPN session tokens, and detailed knowledge of the internal network architecture sitting behind the gateway.On July 14, SonicWall disclosed two vulnerabilities that are being exploited together in the wild:CVEDescriptionCVSSv3CVE-2026-15409SonicWall SMA 1000 server-side request forgery (SSRF) vulnerability10CVE-2026-15410SonicWall SMA 1000 remote code execution vulnerability (RCE)7.2While the advisory does not specify if they were exploited in tandem, together they form a fully remote, unauthenticated path to arbitrary OS command execution on affected appliances.AnalysisCVE-2026-15409 is a SSRF vulnerability affecting the SMA 1000 Workplace interface. This flaw allows a remote, unauthenticated attacker to make network requests to locations of the attacker’s choosing. In practice, SSRF on an internet-facing appliance can serve as a pivot, allowing an attacker to probe internal services, relay authentication material, or reach the AMC in a way that bypasses normal access controls.CVE-2026-15410 is a code injection vulnerability in the Appliance Management Console (AMC). The AMC is the administrative interface used to configure the appliance, manage users, set access policies, and monitor sessions. While this flaw does require the user to be authenticated, the potential chaining of these vulnerabilities makes the exploitation path possible without authentication.These flaws have been exploited in the wild as zero-days. While SonicWall has not provided any details on attribution of which threat actors may be behind the attacks, several SonicWall vulnerabilities have been targeted in the past, including the exploitation of zero-days.Historical exploitation of SonicWall vulnerabilitiesSonicWall products have been a frequent target for attackers over the years. Specifically, the SMA product line has been targeted in the past by ransomware groups, as well as being featured in the Top Routinely Exploited Vulnerabilities list co-authored by multiple United States and International Agencies. Last year, a surge in ransomware activity was tied to the exploitation of SonicWall Gen 7 Firewalls, prompting warnings from multiple security vendors.Given the historical exploitation of SonicWall devices, we put together the following list of known SMA vulnerabilities that have been exploited in the wild:CVEDescriptionTenable Blog LinksYearCVE-2019-7481SonicWall SMA100 SQL Injection Vulnerability12019CVE-2019-7483SonicWall SMA100 Directory Traversal Vulnerability-2019CVE-2021-20016SonicWall SSLVPN SMA100 SQL Injection Vulnerability1, 2, 3, 4, 52021CVE-2021-20038SonicWall SMA100 Stack-based Buffer Overflow Vulnerability1, 2, 32021CVE-2025-23006SonicWall SMA 1000 Deserialization of Untrusted Data Vulnerability12025CVE-2024-40766SonicWall SonicOS Improper Access Control Vulnerability12025CVE-2025-40602SonicWall SMA 1000 Privilege Escalation Vulnerability12025Both CVE-2026-15409 and CVE-2026-15410 have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog with a remediation date of Friday, July 17, despite only being added on July 14. Given the urgency surrounding these vulnerabilities and the historical exploitation of these devices, immediate patching is recommended.Proof of conceptAt the time this blog was published, no proof-of-concept (PoC) code had been published for CVE-2026-15409 or CVE-2026-15410. If and when a public PoC exploit becomes available for these vulnerabilities, we anticipate an increase in exploitation as attackers will attempt to leverage these flaws as part of their attacks.SolutionSonicWall has released patches to address this vulnerability in SMA1000 models 6210, 7210 and 8200v as outlined in the table below:Affected VersionFixed Version12.4.3-0324512.4.3-03453 and later versions12.4.3-0338712.4.3-03453 and later versions12.4.3-0343412.4.3-03453 and later versions12.5.0-0228312.5.0-02835 and later versions12.5.0-0262412.5.0-02835 and later versions12.5.0-0280012.5.0-02835 and later versionsWhile the advisory does not provide any workarounds, it does include indicators of compromise (IoCs) for threat hunters to determine if any exploitation has impacted their devices. We recommend reviewing the advisory for the most up to date IoCs.Identifying affected systemsA list of Tenable plugins for these vulnerabilities can be found on the individual CVE pages for CVE-2026-15409 and CVE-2026-15410 as they’re released. This link will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.Tenable Attack Surface Management customers are able to identify these assets using a filtered search for SonicWall devices:Get more informationSonicWall Security Advisory SNWLID-2026-0008Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.