Outbreak Alert: Iran-linked Cyber Attacks
| FortiRecon Digital Risk Protection (DRP), a SaaS-based service, includes External Attack Surface Management, Brand Protection, and Adversary Centric Intelligence. Adversary Centric Intelligence (ACI): leverages FortiGuard Threat Analysis to provide comprehensive coverage of dark web, open-source, and technical threat intelligence, including threat actor insights to enable organizations to respond proactively assess risks, respond faster to incidents, better understand their attackers, and guard assets. The Vulnerability Intelligence Module under Adversary Centric Intelligence (ACI) provides a realistic view of the impact of the vulnerability based upon chatter and discussion of the same across various external sources such as Darkweb, social media, News / Blogs etc. | |
| CVE ID | CVE-2026-20131 |
| CVE Title | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.00595 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (Interlock Ransomware Operator) |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 3 |
| Darknet Mention(s) | 1 (underc0de) |
| Telegram Mention(s) | 1 (Hacker's TOYS) |
| FortiRecon Intelligence Reporting(s) | 11 (OSINT), 3 (FortiGuard Research), 1 (Technical Intelligence) |
| Vendor Advisory: | |
| CVE ID | CVE-2026-20127 |
| CVE Title | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.01038 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 7 |
| Darknet Mention(s) | 2 (duty_free, underc0de) |
| Telegram Mention(s) | 2 (Proxy Bar) |
| FortiRecon Intelligence Reporting(s) | 14 (OSINT), 4 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2026-1731 |
| CVE Title | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.74328 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | Yes (Silk Typhoon, MuddyWater) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 7 |
| Darknet Mention(s) | 0 |
| Telegram Mention(s) | 1 (Proxy Bar) |
| FortiRecon Intelligence Reporting(s) | 2 (Technical Intelligence), 11 (OSINT), 1 (Darknet), 1 (HUMINT), 10 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2026-1340 |
| CVE Title | A code injection in Ivanti Endpoint Manager Mobile allowing attackers... |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.64618 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | No |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 2 |
| Darknet Mention(s) | 7 (xss, breachforums) |
| Telegram Mention(s) | 0 |
| FortiRecon Intelligence Reporting(s) | 1 (Darknet), 7 (OSINT), 3 (Technical Intelligence), 5 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2026-1281 |
| CVE Title | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.73362 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | Yes (MuddyWater) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 2 |
| Darknet Mention(s) | 7 (xss, breachforums) |
| Telegram Mention(s) | 1 (Proxy Bar) |
| FortiRecon Intelligence Reporting(s) | 10 (OSINT), 1 (Darknet), 5 (Technical Intelligence), 9 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-61882 |
| CVE Title | Oracle E-Business Suite Unspecified Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 91/100 |
| Epss Score | 0.88801 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (Cl0p Ransomware Operators, FIN11, CL0P Ransomware Group, Clop Ransomware Group) |
| Exploited by APT Group(s) | Yes (QuietCrabs, Qilin) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 14 |
| Darknet Mention(s) | 35 (crdclub, xss, rehub, exploit, underc0de) |
| Telegram Mention(s) | 3 (Proxy Bar, SLSH 6.0 part 3 - lapsus$hiny$scatteredwizard) |
| FortiRecon Intelligence Reporting(s) | 9 (Darknet), 23 (OSINT), 7 (Technical Intelligence), 18 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-61757 |
| CVE Title | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 90/100 |
| Epss Score | 0.87758 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (CL0P Ransomware Group) |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 2 |
| Darknet Mention(s) | 0 |
| Telegram Mention(s) | 0 |
| FortiRecon Intelligence Reporting(s) | 1 (Technical Intelligence), 9 (OSINT), 6 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-59287 |
| CVE Title | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 91/100 |
| Epss Score | 0.71617 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | Yes |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 27 |
| Darknet Mention(s) | 10 (rehub, ramp, duty_free, underc0de) |
| Telegram Mention(s) | 5 (, Proxy Bar, LΣҒΔ𝕽ΩLL :israel:) |
| FortiRecon Intelligence Reporting(s) | 6 (Darknet), 3 (Technical Intelligence), 19 (OSINT), 12 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-5777 |
| CVE Title | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability |
| NVD Severity | HIGH |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 92/100 |
| Epss Score | 0.69815 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | Yes (MuddyWater) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 1 |
| Available POC exploit(s) | 0 |
| Darknet Mention(s) | 23 (exploit, ramp, xssf, damagelib) |
| Telegram Mention(s) | 4 (Ralf Hacker Channel, Волосатый бублик, Proxy Bar) |
| FortiRecon Intelligence Reporting(s) | 2 (Darknet), 21 (OSINT), 14 (FortiGuard Research), 1 (Technical Intelligence) |
| Vendor Advisory: |
| CVE ID | CVE-2025-55182 |
| CVE Title | Meta React Server Components Remote Code Execution Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.65077 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (CL0P Ransomware Group) |
| Exploited by APT Group(s) | Yes (UNC5454, UNC5342, Qilin, MuddyWater) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 450 |
| Darknet Mention(s) | 79 (crdclub, exploit, underc0de, duty_free, darkmarket, crimestate, damagelib, gerki, darkforums) |
| Telegram Mention(s) | 18 (maulnism1337, 404 CREW CYBER TEAM Chat, Proxy Bar, I҉n҉v҉e҉s҉t҉i҉g҉a҉t҉i҉o҉n҉ A҉n҉o҉n҉Y҉m҉o҉u҉s҉, 313 Team, Linuxor ?, NNM057(16) eng vers, We Leak Database, Cyber Fattah team, Ralf Hacker Channel, 404 CREW CYBER TEAM, Chat Cyber Islamic resistance, Cyber Islamic resistance-Axis:palestinian_territories:) |
| FortiRecon Intelligence Reporting(s) | 8 (Darknet), 29 (Technical Intelligence), 29 (OSINT), 20 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-52691 |
| CVE Title | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.8729 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes |
| Exploited by APT Group(s) | Yes (MuddyWater) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 10 |
| Darknet Mention(s) | 2 (crdclub, underc0de) |
| Telegram Mention(s) | 3 (Rakyat Digital Crew, wickzzoy, TikusXploit) |
| FortiRecon Intelligence Reporting(s) | 4 (FortiGuard Research), 7 (OSINT), 1 (Darknet), 1 (Technical Intelligence) |
| Vendor Advisory: |
| CVE ID | CVE-2025-24016 |
| CVE Title | Wazuh Server Deserialization of Untrusted Data Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 91/100 |
| Epss Score | 0.93874 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (FunkSec) |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 8 |
| Darknet Mention(s) | 1 (xss) |
| Telegram Mention(s) | 1 (Proxy Bar) |
| FortiRecon Intelligence Reporting(s) | 5 (OSINT), 4 (Technical Intelligence), 5 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2025-13223 |
| CVE Title | Google Chromium V8 Type Confusion Vulnerability |
| NVD Severity | HIGH |
| FortiRecon Severity | HIGH |
| FortiRecon Score | 70/100 |
| Epss Score | 0.02686 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 0 |
| Darknet Mention(s) | 1 (underc0de) |
| Telegram Mention(s) | 0 |
| FortiRecon Intelligence Reporting(s) | 9 (OSINT), 1 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2023-36899 |
| CVE Title | ASP.NET Elevation of Privilege Vulnerability |
| NVD Severity | HIGH |
| FortiRecon Severity | MEDIUM |
| FortiRecon Score | 65/100 |
| Epss Score | 0.70037 |
| Exploited | No |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | No |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 2 |
| Darknet Mention(s) | 0 |
| Telegram Mention(s) | 0 |
| FortiRecon Intelligence Reporting(s) | 1 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2023-29552 |
| CVE Title | Service Location Protocol (SLP) Denial-of-Service Vulnerability |
| NVD Severity | HIGH |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 90/100 |
| Epss Score | 0.92962 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | No |
| Exploited by APT Group(s) | No |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 0 |
| Available POC exploit(s) | 0 |
| Darknet Mention(s) | 0 |
| Telegram Mention(s) | 0 |
| FortiRecon Intelligence Reporting(s) | 2 (OSINT), 1 (FortiGuard Research) |
| Vendor Advisory: |
| CVE ID | CVE-2021-45046 |
| CVE Title | Apache Log4j2 Deserialization of Untrusted Data Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 92/100 |
| Epss Score | 0.9434 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (Wazawaka, Avos ransomware group) |
| Exploited by APT Group(s) | Yes (TunnelVision, Magic Hound, COBALT MIRAGE, DEV-0270, TEMP.Zagros) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 2 |
| Available POC exploit(s) | 49 |
| Darknet Mention(s) | 2 (ramp) |
| Telegram Mention(s) | 2 (Hacking tools y tal) |
| FortiRecon Intelligence Reporting(s) | 13 (OSINT), 11 (FortiGuard Research), 18 (Technical Intelligence) |
| Vendor Advisory: |
| CVE ID | CVE-2021-44228 |
| CVE Title | Apache Log4j2 Remote Code Execution Vulnerability |
| NVD Severity | CRITICAL |
| FortiRecon Severity | CRITICAL |
| FortiRecon Score | 95/100 |
| Epss Score | 0.94358 |
| Exploited | Yes |
| Exploited by Ransomware Group(s) | Yes (Mimo, AvosLocker Ransomware Operators, EMPEROR DRAGONFLY, Karakurt Ransomware Operators, Khonsari Ransomware, DEV-0270, TellYouThePass Ransomware Operators, Black Basta Ransomware Group, DragonForce Ransomware Operator, Wazawaka, Avos ransomware group) |
| Exploited by APT Group(s) | Yes (Andariel, APT38, TA453, COBALT MIRAGE, DEV-0270, TunnelVision, Deep Panda, Stonefly, GOP, Parastoo, Operation DarkSeoul, Teal Kurma, Magic Hound, Onyx Sleet, APT41, TEMP.Zagros, Budworm, Winnti Umbrella) |
| Included in CISA KEV List | Yes |
| Available working exploit(s) | 17 |
| Available POC exploit(s) | 489 |
| Darknet Mention(s) | 19 (raidforums, xss, exploit, breachforums, ramp, imhatimi, duty_free, validmarket) |
| Telegram Mention(s) | 10 (Hacking tools y tal, DC8044 F33d, Stega Intelligence, Systemadminbd Official (BCF), Exploit Developers, Ralf Hacker Channel) |
| FortiRecon Intelligence Reporting(s) | 59 (Technical Intelligence), 35 (OSINT), 3 (Darknet), 3 (HUMINT), 48 (FortiGuard Research) |
