Generated · Archived snapshot 13 findings · 7 CVEs
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are under active exploitation across diverse platforms, ranging from enterprise software to consumer devices. GitLab, Forminator WordPress plugin, VMware vCenter, SAP Commerce Cloud, Apple macOS Screen Sharing, and Microsoft Defender all have confirmed exploitation activity, with several carrying maximum CVSS scores of 9.8–10.0.

A suspected China-nexus APT is leveraging the VMware vCenter flaw (CVE-2026-59310) to deploy Babuk-derived ransomware, while Iranian nation-state actors continue evolving the Cavern C2 framework using DNS and Google Apps Script for stealthy communications. The Unisoc VoLTE exploit chain demonstrates a sophisticated two-stage attack achieving full Android kernel access with no vendor fix available, and the Evooo1Bot Linux botnet is actively weaponizing known vulnerabilities to convert edge devices into persistent SOCKS5 proxy infrastructure.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-19478#

  • Description: A critical vulnerability in GitLab Community Edition and Enterprise Edition that allows unauthenticated attackers to remotely modify or delete public projects and user data under certain conditions through the GraphQL API.
  • Impact: Unauthenticated remote modification or deletion of public projects and user data.
  • Status: Security updates released by GitLab; patch available.

CriticalActive exploitationPatchCVE-2026-15748#

  • Description: Critical remote code execution vulnerability in Forminator Forms WordPress plugin (600,000+ active installations) enabling arbitrary code execution via malicious PHP file uploads without authentication.
  • Impact: Full unauthenticated remote code execution on vulnerable WordPress sites.
  • Status: Vulnerability disclosed; patch status not specified in source.

CriticalActive exploitationPatchCVE-2026-54121#

  • Description: Vulnerability allowing a standard domain user to escalate privileges and turn an Enterprise Certificate Authority into a Domain Controller, exposing fundamental PKI trust issues.
  • Impact: Domain compromise via CA privilege escalation; Tier 0 identity infrastructure breach.
  • Status: Patch available; described as "the easy part" with deeper architectural lessons needed.

CriticalActive exploitationMitigateCVE-2026-69414#

  • Description: Zero-day vulnerability in Microsoft Defender disclosed by researcher "Nightmare Eclipse" that bypasses security controls; Microsoft is actively developing a patch.
  • Impact: Defender bypass and potential security control evasion.
  • Status: Zero-day disclosed; Microsoft working on patch; no fix released yet.

CriticalActive exploitationPatchCVE-2026-59310#

  • Description: Severe directory traversal vulnerability in VMware vCenter Server (CVSS 9.8) allowing unauthenticated remote code execution; actively exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware.
  • Impact: Unauthenticated remote code execution leading to ransomware deployment.
  • Status: Newly patched by Broadcom; active exploitation confirmed in the wild.

CriticalActive exploitationPatchCVE-2026-58231#

  • Description: Maximum-severity vulnerability (CVSS 10.0) involving insufficient authorization checks and input validation, allowing unauthenticated attackers to abuse a default authentication client.
  • Impact: Unauthenticated access and potential full compromise of SAP Commerce Cloud instances.
  • Status: Patched; active exploitation attempts observed days after patch release.

CriticalActive exploitationPatchCVE-2026-65400#

  • Description: Critical authentication issue in macOS Screen Sharing component (CVSS 9.8) allowing network-adjacent attackers to bypass authentication; actively exploited to deploy Monero cryptocurrency miners on internet-exposed Macs.
  • Impact: Unauthorized remote access and cryptominer deployment.
  • Status: Recently patched by Apple; active exploitation confirmed by NCSC-NL.

HighObservedInvestigate#

  • Description: Command injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository via crafted GitHub issues triggering malicious workflow execution in .github/workflows/jira_issue.yml containing internal Jira credentials.
  • Impact: Command execution in CI/CD pipeline with access to internal credentials.
  • Status: Disclosed by Wiz researchers; patch status not specified.

CriticalPotentialMonitor#

  • Description: Two-stage exploit chain achieving full Android kernel access on devices with Unisoc modem firmware through a VoLTE video call; second stage published August 17, 2026, following initial RCE disclosure in March 2026.
  • Impact: Full kernel-level compromise via zero-click or one-click VoLTE call.
  • Status: No fix available from chipset maker; exploit code published.

HighActive exploitationPatch#

  • Description: Mirai-derived modular botnet actively exploiting known vulnerabilities in internet-facing gateway devices to enroll them as SOCKS5 proxy nodes, extending beyond DDoS with credential theft and reverse SOCKS relays.
  • Impact: Device compromise, persistent proxy infrastructure, credential theft, network pivoting.
  • Status: Active campaigns observed; exploits known flaws (specific CVEs not enumerated in sources).

HighObservedInvestigate#

  • Description: Model Context Protocol servers exposing enterprise secrets through plaintext configuration files, over-permissioned access, and prompt injection, often before security teams are aware the servers are running.
  • Impact: Silent exposure of sensitive enterprise data and credentials to AI agents.
  • Status: Architectural risk; no specific patch; requires configuration and governance controls.

MediumActive exploitationMonitor#

  • Description: Threat actors acquiring expired domains (50,400 in H1 2026, ~$7M spent) to inherit traffic and reputation, redirecting victims to scams and malware.
  • Impact: Large-scale traffic redirection to malicious content; brand reputation abuse.
  • Status: Ongoing campaign; no technical patch; requires domain monitoring and registration hygiene.

HighObservedInvestigate#

  • Description: Vulnerability at an unnamed service provider exploited to withdraw funds from Commerzbank customer accounts, resulting in €30M fraud; four arrests in Brazil, three charged in Europe.
  • Impact: Direct financial theft from bank customers via service provider compromise.
  • Status: Law enforcement action taken; vulnerability details not disclosed.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities