INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells
| 2026-09-09 20:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 9, 2026, three distinct threat actor clusters were identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. The attackers exploited two vulnerabilities: CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation, while CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. At least six indicators of compromise were reported, including the IP addresses [IOC HIDDEN • LOGIN REQUIRED] and [IOC HIDDEN • LOGIN REQUIRED]. The attackers used various tactics, including authentication bypass, credential theft tools, Cyclops Blink malware, ransomware, reverse shells, and SQL injection vulnerabilities.
Technical Mitigations AI-generated
• Patch Cisco Secure Firewall Management Center (FMC) Software to address CVE-2026-20079 and CVE-2026-20316.
• Apply available hotfixes for SonicWall SMA 1000 Appliances to mitigate CVE-2026-83548, CVE-2026-83549, and CVE-2026-9586.
• Block or hunt for HTTP request/response smuggling vulnerabilities in Kludex Starlette (CVE-2026-48710) using techniques such as URL rewriting and content filtering.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ho•••••.ai
db•••••.log
176.65.•••.•••
8.4.•••.•••
6f98ad••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b037f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
db4911••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops BlinkQilinQilinAgendaAgenda
CVE-2026-24770CVE-2026-24770
CVE-2026-20316CVE-2026-20316
CVE-2026-82329CVE-2026-82329
CVE-2026-48710CVE-2026-48710
CVE-2026-28797CVE-2026-28797
CVE-2026-20079CVE-2026-20079
CVE-2026-49869CVE-2026-49869
CVE-2025-68700CVE-2025-68700
CVE-2026-59822CVE-2026-59822
CVE-2026-9586CVE-2026-9586
CVE-2026-83549CVE-2026-83549
CVE-2026-45312CVE-2026-45312
CVE-2026-42271CVE-2026-42271
CVE-2025-69286CVE-2025-69286
CVE-2026-83548CVE-2026-83548
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2026/09/09
Threat actors exploited exposed RAGFlow instances using flaws like CVE-2026-45312, CVE-2026-28797, and others to establish persistence and steal large language model provider keys.
Click on any entity below to view its context and source!
organisation
Cisco Secure Firewall Management Center
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities.
organisation
Secure Firewall Management Center
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software.
infrastructure
4,000 devices
“Currently Shodan shows that there are approximately 4,000 devices on the internet, with most located within the United States.”
Horizon3 says it has not seen active exploitation of the remaining 11 flaws it discovered earlier.
infrastructure
8.4.0
With CVE-2026-9586 being actively exploited, system administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later as soon as possible, and check for signs of having been targeted in the meantime.
The vendor fixed them in Switchvox version 8.4.0.2, released on July 14.
Sangoma
released patches
for the flaw in Switchvox 8.4.0.2 on July 14, 2026.
infrastructure
Windows
"
Separately, the Windows maker also revealed that malicious actors are breaking into LiteLLM gateways using CVE-2026-42271 and CVE-2026-48710 to deliver an XMRig miner via an ELF binary, but not before fingerprinting the host and terminating com…
data_breach
8.3 Switchvox SMB Edition
The vulnerability in question is
CVE-2026-9586
(CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL su…
"An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
"
Separately, the Windows maker also revealed that malicious actors are breaking into LiteLLM gateways using CVE-2026-42271 and CVE-2026-48710 to deliver an XMRig miner via an ELF binary, but not before fingerprinting the host and terminating com…
Metrics
infrastructure
4,000
Devices
“Currently Shodan shows that there are approximately 4,000 devices on the internet, with most located within the United States.”
Horizon3 says it has not seen active exploitation of the remaining 11 flaws it discovered earlier.
Metrics
infrastructure
8.4.0
Software Version
The vendor fixed them in Switchvox version 8.4.0.2, released on July 14.
With CVE-2026-9586 being actively exploited, system administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later as soon as possible, and check for signs of having been targeted in the meantime.
Sangoma
released patches
for the flaw in Switchvox 8.4.0.2 on July 14, 2026.
Metrics
data_breach
8
Switchvox Smb Edition
The vulnerability in question is
CVE-2026-9586
(CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL su…
"An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).
Intelligence Sources
The Hacker News
2026-09-02
The Hacker News
2026-09-03
BleepingComputer
2026-09-02
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
BleepingComputer
AlienVault OTX
2026-09-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T06:18
Comprehensive Tactical Telemetry
Highly Correlated Entities
35x
organisation
Identified Entity
Cisco Secure Firewall Management Center
entity
15x
vulnerability
Exploited CVE
CVE-2026-20316
cve
14x
timeline
Temporal Reference
2026/08/27
date
9x
attribution
Attributing Entity
KEV
authority
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
malware
Malware Payload
Cyclops Blink
tool
2x
general metric
Cve-2026 Cvss Score
9
cve-2026 cvss score
2x
general metric
Cve-2026
59,822
cve-2026
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Contextual Telemetry
Context Block
20 METRICS
source region
Origin Country
Russian Federation
country
target region
Target Country
United States
country
industry
Targeted Sector
Defense
sector
general metric
Cve-2026 83549
8
cve-2026 83549
general metric
Appliances
1,000
appliances
general metric
Cvss Score
10
cvss score
general metric
48710 Cvss Score
6
48710 cvss score
general metric
Active Exploitation
83,549
active exploitation
general metric
Berri Litellm Flaw
9
berri litellm flaw
infrastructure
Affected Product
Windows
software
general metric
Binding Operational Directive
26
binding operational directive
infrastructure
Devices
4,000
devices
general metric
Remaining Flaws
11
remaining flaws
general metric
Flaws
12
flaws
infrastructure
Software Version
8.4.0
version
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Sep
2
sep
data breach
Switchvox Smb Edition
8
switchvox smb edition
general metric
Instances
4,000
instances
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.