From Late March to Early April 2026: Active Exploits and Supply Chain Attacks Intensify Across…
Executive Summary
From Late March to Early April 2026: Active Exploits and Supply Chain Attacks Intensify Across Enterprise Platforms
Executive Summary
The threat landscape this week reflected continued exploitation of critical vulnerabilities across enterprise infrastructure, development tools, and widely used software platforms. Multiple high-impact flaws were observed being actively leveraged in real-world attacks, highlighting persistent adversary focus on high-value targets. Four vulnerabilities were added to the CISA KEV catalog, affecting Citrix NetScaler ADC, Google Dawn, Trivy, and F5 BIG-IP APM. In parallel, active exploitation was detected in TrueConf video conferencing software, Fortinet FortiClient EMS, and Oracle WebLogic Server, involving vulnerabilities enabling remote code execution and privilege escalation. In parallel, a large-scale supply chain attack targeted Trivy, an open-source tool widely used in CI/CD pipelines, where a vulnerability was exploited by the threat group TeamPCP, with activity first observed on March 19, 2026. Additionally, Check Point Research reported that a vulnerability in TrueConf was exploited as a zero-day in early 2026 as part of the “TrueChaos” campaign, targeting government entities across Southeast Asia, including Thailand, Vietnam, Indonesia, and Malaysia.
1. Trending / Critical Vulnerabilities
This period’s threat landscape saw multiple vulnerabilities added to the CISA KEV catalog, highlighting active exploitation across network infrastructure, supply chain tooling, enterprise platforms, and video conferencing software. These included CVE-2026–33634 in Aqua Security Trivy, an Embedded Malicious Code vulnerability enabling a large-scale supply chain attack that allowed attackers to access sensitive CI/CD data including tokens, SSH keys, cloud credentials, and database secrets, attributed to the threat group TeamPCP. CVE-2026–3055 in Citrix NetScaler ADC and Gateway, an Out-of-Bounds Read vulnerability allowing remote attackers to leak sensitive memory data via SAML-related endpoints when devices are configured as a SAML Identity Provider, was observed under active exploitation in the wild. CVE-2026–5281 in Google Dawn, a Use-After-Free vulnerability affecting multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera, allowed a remote attacker with a compromised renderer process to execute arbitrary code via a crafted HTML page, with Google confirming in-the-wild exploitation. CVE-2025–53521 in F5 BIG-IP APM, initially classified as a denial-of-service issue and later reclassified as a Remote Code Execution vulnerability following new findings in March 2026, saw confirmed in-the-wild exploitation with over 240,000 BIG-IP instances remaining exposed online. Beyond the KEV additions, active exploitation was also observed in CVE-2026–3502 in TrueConf Windows Client, a Download of Code Without Integrity Check vulnerability exploited as part of the “TrueChaos” campaign attributed to a Chinese-nexus threat actor deploying the Havoc C2 framework, CVE-2026–21643 in Fortinet FortiClient EMS, an SQL Injection vulnerability enabling unauthenticated arbitrary code execution via crafted HTTP requests, and CVE-2026–21962 in Oracle WebLogic Server, an Unauthenticated Remote Code Execution vulnerability exploited within hours of public exploit code release.
2. Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Cytellite telemetry this period revealed sustained scanning and exploitation activity targeting network appliances, enterprise platforms, and internet-facing services, highlighting continued adversary focus on high-impact infrastructure. Confirmed in-the-wild exploitation included CVE-2025–5777 in Citrix NetScaler ADC and Gateway, an Out-of-Bounds Read vulnerability exposing sensitive memory data, and CVE-2025–31324 in SAP NetWeaver Visual Composer Metadata Uploader, an Unrestricted File Upload vulnerability enabling attackers to upload dangerous file types to affected systems. Additional actively exploited vulnerabilities included CVE-2024–47176 in OpenPrinting CUPS, an Improper Input Validation vulnerability leading to remote code execution, and CVE-2024–4577 in PHP CGI, an OS Command Injection vulnerability enabling remote code execution on affected systems. Further confirmed exploitation was observed in CVE-2023–4966 in Citrix NetScaler ADC and Gateway, a Buffer Overflow vulnerability leading to sensitive information disclosure, and CVE-2023–38646 in Metabase open source, enabling unauthenticated remote code execution, along with CVE-2023–26801 in LB-LINK routers, a Command Injection vulnerability allowing remote attackers to execute arbitrary commands. Additional risks were identified in CVE-2024–8503 in VICIdial, a SQL Injection vulnerability leading to sensitive information disclosure, CVE-2023–49103 in ownCloud owncloud/graphapi, exposing sensitive configuration and credential data, CVE-2023–31192 in SoftEther VPN, an Information Disclosure vulnerability in the ClientConnect() functionality. Collectively, these findings underscored continued attacker focus on command injection, file upload abuse, memory disclosure, and access control weaknesses across network edge devices, enterprise applications, and open-source platforms, reinforcing the critical need for timely patching, exposure minimization, and continuous monitoring of internet-facing infrastructure.
3. Vulnerabilities Abused by Malware
This period’s threat intelligence highlighted large-scale supply chain compromise and sophisticated multi-stage exploitation campaigns impacting development ecosystems, enterprise collaboration platforms, and CI/CD pipeline infrastructure. According to Check Point Research, CVE-2026–3502 was exploited as a zero-day in early 2026 as part of the “TrueChaos” campaign targeting government entities in Southeast Asia, where attackers controlling on-premises TrueConf servers distributed malicious updates via a compromised update mechanism, leveraging DLL side-loading techniques to deploy implants and ultimately deliver the Havoc C2 framework, with attribution pointing to a Chinese-nexus threat actor based on infrastructure overlaps with ShadowPad activity. According to Sysdig, a wide-reaching supply chain attack carried out by the threat group TeamPCP beginning March 19, 2026, targeted Trivy, exploiting CVE-2026–33634 to forcibly override trusted GitHub Action tags and silently redirect CI/CD pipeline versions to malicious commits without any visible changes to release metadata. The campaign subsequently expanded to compromise Checkmarx KICS, Checkmarx AST, OpenVSX extensions, and the LiteLLM AI gateway library, with malicious PyPI packages embedding credential-stealing malware that exfiltrated stolen data to attacker-controlled infrastructure. Post-exploitation activity included deployment of the PCP InfoStealer to harvest SSH keys, cloud access tokens, and cryptocurrency wallets, along with persistent backdoors in Kubernetes clusters and propagation of the self-replicating CanisterWorm worm across the JavaScript npm ecosystem. In total, more than 20,000 repositories were considered potentially vulnerable, with TeamPCP claiming to have exfiltrated hundreds of gigabytes of data and over 500,000 compromised accounts, collectively underscoring the escalating threat posed by supply chain weaponization and abuse of trusted software distribution channels.
4. OSS Trending vulnerabilities observed this week
This period’s open-source threat activity revealed multiple vulnerabilities across widely used development frameworks, content management systems, and workflow automation platforms, highlighting continued risks within software supply chains and developer tooling ecosystems. Notable issues included CVE-2026–22738 in Spring AI (Maven), a Spring Expression Language (SpEL) Injection vulnerability enabling attackers to execute arbitrary expressions and potentially achieve remote code execution within affected Spring-based applications. CVE-2026–30880 in baserCMS (Packagist) introduced an OS Command Injection vulnerability allowing attackers to execute arbitrary operating system commands on affected installations. CVE-2026–34070 in the LangChain Framework (PyPI) exposed systems to a Path Traversal vulnerability, enabling unauthorized access to files and directories outside the intended scope. CVE-2026–34156 in NocoBase’s Workflow JavaScript node (npm) introduced a Sandbox Escape vulnerability, allowing attackers to break out of the restricted execution environment and execute arbitrary code on the underlying host. CVE-2026–34449 in SiYuan (Go) presented a Cross-Origin Remote Code Execution vulnerability, enabling remote attackers to execute arbitrary code across origin boundaries in affected deployments.
5. Pre-NVDs vulnerabilities observed this week
This period’s early vulnerability disclosures revealed multiple security issues across network tools, enterprise data management platforms, and widely used development utilities, highlighting emerging risks across both infrastructure and end-user software. Notable findings included CVE-2026–3690 in OpenClaw, an Authentication Bypass vulnerability enabling attackers to circumvent authentication controls and gain unauthorized access to affected systems. CVE-2026–4788 in IBM Tivoli Netcool Impact introduced an Insertion of Sensitive Information into Log File vulnerability, exposing credentials and sensitive operational data through insufficiently protected log outputs. CVE-2026–5055 in NoMachine Device Server presented a Local Privilege Escalation vulnerability, allowing locally authenticated attackers to elevate privileges and gain elevated system access on affected deployments. CVE-2026–28264 in Dell PowerProtect Data Manager exposed an Incorrect Permission Assignment for Critical Resource vulnerability, potentially enabling unauthorized access to or modification of sensitive protected data management components. CVE-2026–34982 in Vim introduced an OS Command Injection vulnerability, allowing attackers to execute arbitrary operating system commands through maliciously crafted input processed by the affected text editor.
Conclusion
Collectively, these developments highlight a threat landscape driven by active exploitation, supply chain compromises, and coordinated campaigns targeting critical platforms. The convergence of KEV-listed vulnerabilities and real-world attacks underscores the need for rapid remediation and continuous visibility. Leveraging platforms like Loginsoft Vulnerability Intelligence (LOVI) enables organizations to track exploited vulnerabilities in real time, prioritize risks, and strengthen proactive defense strategies.
For more details, check out the full report.
메타데이터
- post_id
- 0e41d5bd3f60
- slug
- from-late-march-to-early-april-2026-active-exploits-and-supply-chain-attacks-intensify-across-0e41d5bd3f60
- url
- https://medium.com/@Loginsoft/from-late-march-to-early-april-2026-active-exploits-and-supply-chain-attacks-intensify-across-0e41d5bd3f60
- canonical_url
- https://medium.com/@Loginsoft/from-late-march-to-early-april-2026-active-exploits-and-supply-chain-attacks-intensify-across-0e41d5bd3f60
- author_url
- https://medium.com/@Loginsoft
- status
- ok
- fetched_at
- 2026-06-20 20:29:01