Generated · Archived snapshot 7 findings · 1 CVE
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are under active exploitation across diverse technology stacks, with threat actors ranging from ransomware gangs to state-sponsored espionage groups. Cisco's Secure Firewall Management Center authentication bypass (CVE-2026-20079) has been confirmed exploited by both ransomware operators and state-sponsored actors, prompting CISA to mandate federal patching by September 12.

Simultaneously, a novel exploit kit dubbed BlueMoon—chaining zero-day vulnerabilities in Microsoft Windows and Google Chrome—has been deployed by at least four China-aligned espionage clusters including APT31 within a single week. Ransomware groups are also actively exploiting a critical WatchGuard Firebox RCE flaw, while an AI-driven campaign leveraging hundreds of autonomous agents has compromised over 440 PaperCut NG/MF instances globally.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-20079#

  • Description: A maximum-severity authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) software that allows unauthenticated attackers to gain administrative access to the management platform.
  • Impact: Full administrative control over the Secure Firewall Management Center, enabling configuration changes, policy manipulation, and potential lateral movement to managed firewalls.
  • Status: Actively exploited in the wild by three separate threat clusters including ransomware gangs and state-sponsored actors. Cisco has released patches; CISA added to KEV catalog with September 12, 2026 federal deadline.

CriticalActive exploitationPatch#

  • Description: A critical remote code execution vulnerability in WatchGuard Firebox firewall appliances that allows unauthenticated attackers to execute arbitrary code.
  • Impact: Complete device compromise, enabling network pivoting, traffic interception, and persistent access to victim networks.
  • Status: CISA confirmed ransomware gangs are actively exploiting this flaw in ransomware attacks. Originally flagged as actively exploited in December 2025.

CriticalActive exploitationPatch#

  • Description: A pair of recently disclosed security flaws in PaperCut NG/MF print management software that, when chained, enable unauthenticated remote code execution.
  • Impact: Full server compromise allowing data theft, ransomware deployment, and lateral movement across organizational networks.
  • Status: Actively exploited in a global campaign compromising 395–440+ organizations. Attack leveraged hundreds of AI agents to automate exploit development and deployment at scale. Attributed to a suspected Russian-speaking threat actor operating from IP 45.142.193.132.

CriticalActive exploitationPatch#

  • Description: A previously undocumented exploit kit chaining multiple zero-day vulnerabilities in Microsoft Windows and Google Chrome to achieve remote code execution and sandbox escape.
  • Impact: Initial access and privilege escalation on fully patched Windows and Chrome installations, enabling espionage payload deployment without user interaction.
  • Status: Actively exploited in the wild by at least four espionage-motivated threat activity clusters. First in-the-wild use attributed to APT31 (Bronze Vinewood, Judgement Panda, JungleBamboo); three additional China-aligned groups deployed the kit within a single week.

Severity unknownActive exploitationPatch#

  • Description: A second recently patched vulnerability in Cisco Secure Firewall Management Center (FMC) distinct from CVE-2026-20079, also exploited by threat actors.
  • Impact: Additional attack surface for compromising FMC appliances; specific impact details not disclosed in public reporting.
  • Status: Exploited by three separate threat clusters alongside CVE-2026-20079 in combined campaigns linking ransomware and state-sponsored activity.

CriticalPotentialPatch#

  • Description: Two critical vulnerabilities (CVSS 9.8) in Check Point Security Gateways and Security Management products related to VPN certificate handling, enabling unauthenticated remote code execution under specific undisclosed conditions.
  • Impact: Potential unauthenticated RCE on firewall appliances and management servers, leading to network compromise.
  • Status: Patches released; no confirmed active exploitation reported. Exploitation requires "specific conditions" not publicly described by vendor.

Severity unknownPotentialMonitor#

  • Description: A zero-day exploit for Windows Defender published by a disgruntled security researcher as part of an ongoing vendetta against Microsoft.
  • Impact: Potential bypass or disablement of Windows Defender protections, facilitating malware execution and persistence.
  • Status: Proof-of-concept exploit published; no confirmed reports of active exploitation in the wild beyond the researcher's disclosure.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities