← Back to list

New KEV Additions, Active Exploits and malware campaigns signal a high-stakes week

Executive Summary

Loginsoft · 2026-03-06 14:00 · 0 claps · 4.2 min read
#cybersecurity #lovi #vulnerabilityintelligence #cisakev #exploitkit
Open on Medium ↗
Wiki topics: MKT · Marketing · General 🔒 · Cybersecurity 🥊 · Combat Sports

New KEV Additions, Active Exploits and malware campaigns signal a high-stakes week

Executive Summary

This week’s threat landscape was dominated by a wave of active exploitations and newly cataloged vulnerabilities, as CISA added two critical flaws to its KEV catalog — one affecting Broadcom VMware Aria Operations and another impacting approximately 234 Qualcomm chipsets — while Cisco Catalyst SD-WAN Manager continued to trend with two additional vulnerabilities actively exploited in the wild, signaling persistent attacker interest in network orchestration platforms. On the threat activity front, APT28 leveraged the Microsoft zero-day in a coordinated state-sponsored campaign, while Akamai SIRT observed Zerobot botnet operators exploiting vulnerabilities in Tenda AC1206 routers and the n8n automation platform. Additional intrusion activity involved exploitation of Apache ActiveMQ to deploy LockBit ransomware, alongside the Coruna iOS exploit kit circulating among multiple threat actors, illustrating how advanced exploit capabilities are increasingly shifting from espionage operations into broader criminal abuse.

1. Trending / Critical Vulnerabilities

This week’s threat landscape was shaped by active exploitation across network infrastructure, virtualization management platforms, and mobile hardware ecosystems, with several vulnerabilities newly added to the CISA KEV catalog. Cisco Catalyst SD-WAN environments were impacted by multiple flaws, including CVE-2026–20122, an arbitrary file overwrite vulnerability enabling privilege escalation through API abuse, CVE-2026–20127, an authentication bypass allowing unauthenticated administrative access, and CVE-2026–20128, an information disclosure issue exposing sensitive credential files to low-privileged users. Additional exploitation activity involved CVE-2022–20775, a path traversal vulnerability leveraged in chained attacks to escalate privileges to root within SD-WAN deployments. Beyond network infrastructure, Broadcom VMware Aria Operations faced CVE-2026–22719, a command injection flaw permitting unauthenticated remote code execution, while Qualcomm chipsets were impacted by CVE-2026–21385, a memory corruption vulnerability affecting hundreds of hardware platforms and observed in limited targeted attacks. Collectively, these KEV additions highlight continued attacker focus on management interfaces, authentication controls, and widely deployed enterprise and hardware platforms, reinforcing the urgency of rapid patching and strict access governance.

2. Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Cytellite telemetry this week revealed concentrated scanning and exploitation pressure across web application firewalls, application delivery controllers, enterprise platforms, and embedded infrastructure, highlighting sustained adversary focus on exposed internet-facing services. High-severity weaknesses were observed in Tenda O3V2 devices, including CVE-2025–7417 involving improper memory buffer restrictions and CVE-2025–7414 enabling OS command injection, suggesting continued reconnaissance against IoT and edge appliances. Additional enterprise-facing exposure included Fortinet FortiWeb — CVE-2025–64446 through relative path traversal, Citrix NetScaler ADC and NetScaler Gateway — CVE-2025–5777 involving out-of-bounds read conditions, and Hoverfly — CVE-2025–54123 enabling command injection within API simulation environments. Confirmed in-the-wild exploitation was recorded for Samsung MagicINFO 9 — CVE-2025–4632 via path traversal, Ivanti Endpoint Manager Mobile — CVE-2025–4427 through authentication bypass, Langflow — CVE-2025–3248 lacking authentication for critical functionality, Craft CMS — CVE-2025–32432 enabling remote code execution, and SAP NetWeaver — CVE-2025–31324 involving unrestricted access conditions, several of which are tracked in the CISA KEV catalog. The clustering of command injection, authentication bypass, remote execution, and memory-handling vulnerabilities underscores persistent targeting of administrative interfaces and enterprise management platforms, reinforcing the need for KEV-driven patch prioritization and continuous external attack surface monitoring.

3. Vulnerabilities Abused by Malware

This week’s threat intelligence highlighted active exploitation across enterprise software, automation platforms, messaging infrastructure, and mobile ecosystems by both state-sponsored and financially motivated actors. APT28 was linked to the zero-day exploitation of Microsoft vulnerability CVE-2026–21513, enabling file-based attacks through malicious HTML or LNK shortcuts to bypass security protections and execute code. Concurrently, the Zerobot Mirai-based botnet campaign targeted Tenda AC1206 routers and the n8n workflow automation platform through CVE-2025–7544 and CVE-2025–68613, reflecting a shift toward exploiting enterprise automation systems beyond traditional IoT devices. Additional intrusion activity involved the exploitation of Apache ActiveMQ vulnerability CVE-2023–46604 to gain initial access and ultimately deploy LockBit ransomware following privilege escalation and lateral movement. Meanwhile, Google Threat Intelligence Group identified the Coruna exploit kit leveraging multiple Apple vulnerabilities across iOS versions 13 through 17.2.1, with threat clusters UNC6353 and UNC6691 deploying the PlasmaLoader payload and repurposing advanced exploits originally linked to Operation Triangulation. These campaigns collectively illustrate a growing trend of multi-stage attacks where exploit frameworks, botnets, and ransomware operations converge to target exposed enterprise infrastructure and mobile platforms.

4. OSS Trending vulnerabilities observed this week

This week’s open-source threat activity exposed multiple high-impact vulnerabilities across major development ecosystems, reinforcing persistent software supply-chain risk. Unsafe deserialization in datapizza-ai — CVE-2026–2970 within PyPI and deserialization flaws in Apache Camel — CVE-2026–25747 affecting Maven highlighted continued object handling weaknesses. Command execution exposure surfaced through OS command injection in OliveTin — CVE-2026–27626 in Go and remote code execution in n8n — CVE-2025–68613 within npm. Memory safety risks were also observed in ImageMagick’s DJVU handler CVE-2026–27799 impacting NuGet environments. Together, these issues emphasize how deserialization, injection, and memory handling flaws continue to drive cross-ecosystem exploitation risk.

5. Pre-NVDs vulnerabilities observed this week

This week’s early disclosures highlighted a diverse set of vulnerabilities affecting industrial monitoring systems, media streaming platforms, business intelligence tools, development libraries, and endpoint security software, indicating emerging risk areas ahead of potential exploitation. Identified issues included an authentication bypass vulnerability in Socomec DIRIS A-40 — CVE-2026–2491 that could allow unauthorized access to device functionality, alongside an unauthenticated SQL injection flaw in AVideo — CVE-2026–28501 exposing backend databases to manipulation. Additional exposure was observed in OpenChatBI — CVE-2026–28795 through path traversal conditions that may permit unauthorized file access, while FasterXML Jackson Maven — CVE-2026–29062 faced denial-of-service risks triggered by excessive JSON nesting. Endpoint security infrastructure was also affected, with Trend Micro Apex One Security Agent iCore Service — CVE-2025–71214 impacted by a local privilege escalation vulnerability. Collectively, these disclosures highlight the importance of proactive patch assessment and defensive readiness before vulnerabilities transition into active exploitation.

Conclusion

The week’s developments reinforce a hard truth: modern attacks rarely rely on a single flaw — they thrive on chaining vulnerabilities across infrastructure, applications, and devices to maximize operational impact. From KEV additions affecting VMware and Qualcomm platforms to active exploitation involving Zerobot botnet activity, and advanced exploit frameworks like Coruna, adversaries continue to blend multiple weaknesses into coordinated attack paths. These patterns highlight the limits of reactive patching and the growing need for intelligence-driven vulnerability prioritization. Loginsoft Vulnerability Intelligence (LOVI) helps security teams track exploited vulnerabilities, emerging threat activity, and sector-relevant risks in real time enabling faster remediation and stronger defensive readiness.

For more details, check out the full report.


메타데이터
post_id
e4375629dceb
slug
new-kev-additions-active-exploits-and-malware-campaigns-signal-a-high-stakes-week-e4375629dceb
url
https://medium.com/@Loginsoft/new-kev-additions-active-exploits-and-malware-campaigns-signal-a-high-stakes-week-e4375629dceb
canonical_url
https://medium.com/@Loginsoft/new-kev-additions-active-exploits-and-malware-campaigns-signal-a-high-stakes-week-e4375629dceb
author_url
https://medium.com/@Loginsoft
status
ok
fetched_at
2026-06-20 20:29:01