پارتیان

FortiGuard Labs | FortiGuard Center - Threat Signal Report

The Threat Signal created by the FortiGuard Labs is intended to provide you with insight on emerging issues that are trending within the cyber threat landscape. The Threat Signal will provide concise technical details about the issue, mitigation recommendations and a perspective from the FortiGuard Labs team in an FAQ style format.

What is the Vulnerability?

FortiGuard Labs is tracking an exploitation risk associated with CVE-2026-42533, a heap-based buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus. The flaw occurs when the map directive uses regex matching and capture variables in a specific configuration pattern. An unauthenticated remote attacker can send crafted HTTP requests that may crash the NGINX worker process, resulting in denial of service, and potentially achieve remote code execution when ASLR is disabled or bypassed.

The vulnerability was publicly disclosed by F5 on July 15, 2026, with NGINX releasing fixed versions the same day.

Fortinet has conducted an internal security review of products and services that use NGINX. Based on the current assessment, Fortinet products are not affected by CVE-2026-42533.

What is the Recommended Mitigation?

Affected products:
NGINX Open Source 0.9.6–1.30.3 and 1.31.0–1.31.2
NGINX Plus R33–R36
NGINX Plus R37 37.0.0.1–37.0.2.1
NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and other F5/NGINX products with affected bundled versions.

Organizations should:
• Upgrade NGINX Open Source to 1.30.4 or 1.31.3 or later, depending on the deployment branch.
• Upgrade NGINX Plus to a fixed release, including R36 P7 or 37.0.3.1 where applicable.
• Review NGINX configurations for map directives using regex captures and confirm whether vulnerable variable-reference patterns are present.
• Prioritize Internet-facing NGINX deployments and reverse proxies.
• Deploy WAF protections to detect and block malicious HTTP requests targeting vulnerable NGINX configurations while patching is underway.
• Monitor NGINX worker-process crashes, abnormal HTTP requests, and other indicators of attempted exploitation.

What FortiGuard Coverage is available?

• FortiGuard IPS Service: Detects and blocks network-based attacks targeting vulnerable NGINX assets. Intrusion Prevention | FortiGuard Labs
• FortiWeb: Provides mitigation for CVE-2026-42533 through a custom signature and HTTP protocol constraint to help protect vulnerable NGINX deployments while patching is underway. Technical Tip: Defending against 2026-42533 with FortiWeb | Community
• FortiGuard Vulnerability Management: Identifies vulnerable NGINX assets and helps prioritize remediation based on exposure and risk.
• FortiGuard Incident Response Service: FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Attack?

Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.

While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk.

The activity does not involve a specific CVE. Instead, attackers are taking advantage of Internet-exposed PLCs, weak or default credentials, and inadequate access controls to obtain unauthorized access to OT environments.

Once access to an exposed PLC is obtained, attackers may manipulate configurations, operating parameters, or connected industrial processes. Such access can interfere with normal operations and potentially affect the availability and reliability of water and wastewater services.

What is the recommended Mitigation?

• Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs.
• Change default credentials and enforce strong, unique passwords for PLCs and associated OT systems.
• Implement access control lists (ACLs) to restrict communications to authorized devices and expected sources.
• Restrict remote access to OT environments and require secure authentication for authorized users.
• Monitor PLC configurations and network activity for unauthorized changes, including unexpected modifications to IP addresses, passwords, or operating parameters.
• Segment OT and IT networks to limit lateral movement following a compromise.
• Review exposed PLCs and other Internet-facing OT assets and remove unnecessary public access.
• Maintain offline backups of PLC configurations to support recovery if unauthorized changes or operational disruptions occur.

The FBI specifically recommends removing PLCs from direct Internet exposure, using strong unique passwords, and implementing ACLs to restrict communications

What FortiGuard Coverage is available?

• FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets. OT App Detection | FortiGuard Labs
• FortiGuard IPS Service: Detects and blocks network-based attacks targeting exposed OT/ICS services and PLC infrastructure.
• FortiGuard Web Filtering: Blocks access to known malicious infrastructure associated with threat activity.
• FortiGuard Antivirus & Behavior Detection: Detects malicious payloads that may be delivered following network compromise.
• FortiGuard IOC Service: Identifies known indicators associated with malicious infrastructure and post-compromise activity.
• FortiGuard Incident Response: Supports investigation, containment, and recovery following an OT/ICS compromise.

What is the Attack?

FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed.

Successful exploitation may allow attackers to:
• Execute arbitrary code on the web server.
• Create unauthorized administrator accounts.
• Deploy web shells or persistent backdoors.
• Steal sensitive website and database contents.
• Install malware or ransomware.
• Use compromised servers for further attacks.

What is the recommended Mitigation?

Affected Versions:
WordPress 6.9.0 – 6.9.4
WordPress 7.0.0 – 7.0.1
WordPress 7.1 Beta

Organizations should immediately:
• Upgrade WordPress to the latest patched release (6.9.5, 7.0.2, or later).
• Restrict unnecessary exposure of WordPress administrative interfaces.
• Monitor for unauthorized administrator account creation.
• Review web server logs for suspicious REST API batch endpoint requests.
• Scan for web shells and other indicators of compromise.
• Apply network protections capable of detecting SQL injection and exploitation attempts.

What FortiGuard Coverage is available?

  • FortiGuard IPS Service - Detects and blocks exploitation attempts targeting the WP2Shell vulnerability chain. Intrusion Prevention | FortiGuard Labs

  • FortiGuard Web Application Firewall (WAF) - Protects against SQL injection and malicious REST API requests. Web Application Security | FortiGuard Labs

  • FortiGuard Web Filtering - Blocks access to known malicious infrastructure.

  • FortiGuard Antivirus & Behavior Detection - Detects malware and web shells deployed after successful exploitation.

  • FortiGuard IOC Service - Identifies indicators associated with compromised WordPress servers.

  • FortiGuard Incident Response - Assists with investigation, containment, and recovery following compromise.

What is the Attack?

A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks.

The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations.

What is the recommended Mitigation?

Organizations using PTC Windchill or FlexPLM should:
• Apply the latest vendor security updates immediately.
• Verify whether systems are internet accessible and restrict external exposure where possible.
• Hunt for JSP web shells within the /Windchill/login/ directory.
• Review logs for suspicious requests targeting Windchill login endpoints.
• Rotate credentials and perform a full compromise assessment if exploitation is suspected.

What FortiGuard Coverage is available?

• FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution. Intrusion Prevention | FortiGuard Labs
• FortiGuard Antivirus & Behavior Detection Service identifies and blocks malicious payloads and suspicious post-exploitation behavior associated with Cl0p intrusion activity.
• FortiGuard Web Filtering Service prevents access to known malicious domains, command-and-control (C2) infrastructure, and phishing sites used during the attack lifecycle.
• FortiGuard IOC Service provides up-to-date indicators of compromise (IOCs), enabling security teams to identify affected systems, detect attacker activity, and accelerate threat hunting.
• FortiGuard Incident Response Service assists organizations with incident investigation, containment, forensic analysis, eradication of attacker persistence, and recovery following a confirmed compromise.

What is the Vulnerability?

FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.

Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting the need for immediate patching and monitoring of vulnerable deployments.

What is the recommended Mitigation?

• Upgrade SP Page Builder to version 6.6.2 or later.
• Restrict public access to Joomla administrative interfaces.
• Prevent PHP execution from upload/media directories.
• Monitor for unexpected PHP files and newly created administrator accounts.
• Review web server logs for suspicious POST requests targeting the SP Page Builder upload endpoint.

What FortiGuard Coverage is available?

• FortiGuard Intrusion Prevention System (IPS) protects against exploitation attempts targeting vulnerable SP Page Builder deployments. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious domains, command-and-control infrastructure, and payload hosting locations associated with post-exploitation activity.
• FortiGuard Antivirus detects and blocks malicious payloads, web shells, backdoors, and other malware that attackers may deploy after successfully exploiting vulnerable Joomla installations.
• FortiEDR detects suspicious post-exploitation activities, including unauthorized command execution, web shell execution, persistence attempts, credential theft, and lateral movement from compromised Joomla servers.
• FortiGuard Incident Response Service helps organizations investigate suspected compromises, identify attacker activity, determine the scope of impact, and support containment, remediation, and recovery efforts following exploitation.

What is the Vulnerability?

Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands.

The vulnerabilities impact UniFi OS deployments used to manage enterprise networking infrastructure, including gateways, network controllers, video surveillance, and access control systems. Researchers have publicly demonstrated the exploit chain, and the vulnerabilities have been confirmed as actively exploited in the wild. Organizations should immediately upgrade affected systems and restrict management interfaces from Internet exposure.

Successful exploitation could allow attackers to:
• Obtain root-level remote code execution.
• Completely compromise UniFi OS devices.
• Steal administrative credentials and configuration data.
• Modify firewall, VPN, and network settings.
• Deploy malware or ransomware.
• Pivot into internal enterprise networks.

What is the recommended Mitigation?

Organizations should:

• Immediately upgrade to the latest patched UniFi OS release.
• Restrict UniFi management interfaces to trusted administrative networks.
• Avoid exposing UniFi OS management portals directly to the Internet.
• Monitor logs for suspicious authentication attempts and command execution.
• Review systems for indicators of compromise if Internet exposure existed prior to patching.
• Apply network segmentation and least-privilege administrative access.

What FortiGuard Coverage is available?

• FortiGuard Intrusion Prevention System (IPS) protects against exploit attempts. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
• FortiGuard Antivirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
• FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Vulnerability?

FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code.

CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, enabling complete device compromise without valid credentials.

Shortly after disclosure, watchTowr published a detailed technical analysis and public PoC, significantly lowering the barrier to exploitation and increasing the likelihood of opportunistic attacks.

Ivanti Sentry is an enterprise mobile gateway that provides secure access to corporate email, applications, and content for managed mobile devices. Organizations with internet-exposed Ivanti Sentry appliances should prioritize patching immediately, as attackers are actively attempting to exploit vulnerable systems.

What is the recommended Mitigation?

Affected:
Ivanti Sentry 10.5.1 and earlier
Ivanti Sentry 10.6.1 and earlier
Ivanti Sentry 10.7.0 and earlier

Fixed:
10.5.2
10.6.2
10.7.1

Recommended Actions
• Immediately upgrade to Ivanti Sentry 10.5.2, 10.6.2, or 10.7.1.
• Assume internet-exposed, unpatched appliances may already be compromised.
• Review administrative accounts for unauthorized additions.
• Search for web shells, persistence mechanisms, and suspicious root-level processes.
• Rotate credentials and invalidate tokens if compromise is suspected.
• Monitor for exploitation attempts and anomalous outbound connections.
• Enable IPS protections and virtual patching while emergency updates are being deployed.

What FortiGuard Coverage is available?

• FortiGuard IPS protects against exploit attempts targeting vulnerable Ivanti Sentry appliances. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
• FortiGuard AntiVirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
• FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Attack?

A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server.

Security researchers have demonstrated that the vulnerability can be leveraged toward pre-authentication remote code execution (RCE) under certain conditions, and active exploitation has been confirmed. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, making it a high-priority patching target for organizations running exposed Splunk Enterprise instances.

An attacker who successfully exploits CVE-2026-20253 may be able to:
• Create or truncate arbitrary files on the target server.
• Bypass authentication protections.
• Potentially achieve pre-authentication remote code execution.
• Disrupt Splunk services.

What is the recommended Mitigation?

Affected:
Splunk Enterprise 10.2 prior to 10.2.4
Splunk Enterprise 10.0 prior to 10.0.7

Upgrade to:
Splunk Enterprise 10.2.4 or later
Splunk Enterprise 10.0.7 or later

If immediate patching is not possible:
• Disable the PostgreSQL sidecar service as recommended by Splunk.
• Restrict network access to Splunk management interfaces.
• Monitor for unexpected file creation or service behavior.
• Review logs for suspicious unauthenticated access attempts.

What FortiGuard Coverage is available?

• FortiGuard IPS provides protection against exploit attempts targeting vulnerable services.
• FortiGuard Web Filtering blocks access to known malicious infrastructure used during exploitation.
• FortiGuard AntiVirus detects and blocks malware payloads delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized file modifications and persistence techniques.
• FortiGuard Incident Response Service assists organizations in investigating and determining the scope of compromise, and supporting remediation efforts following exploitation.

What is the Attack?

Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign primarily targeted higher education institutions, with approximately 68% of identified victims belonging to the education sector.

Organizations running internet-accessible Oracle PeopleSoft Environment Management components are at highest risk. Successful exploitation enables unauthenticated remote code execution, deployment of remote management tooling, data theft, and extortion activities.

An attacker who successfully exploits CVE-2026-35273 can:
• Execute arbitrary code on vulnerable Oracle PeopleSoft servers.
• Establish persistent remote access using legitimate administration tools.
• Conduct reconnaissance of enterprise infrastructure and configurations.
• Move laterally within the environment.
• Steal sensitive employee, student, financial, and operational data.
• Conduct extortion or ransomware-style operations using stolen data.

What is the recommended Mitigation?

Potentially exposed systems include:
Internet-facing Oracle PeopleSoft deployments.

• Immediately apply Oracle's security updates for CVE-2026-35273.
• Restrict external access to PeopleSoft Environment Management services.
• Review logs for suspicious activity between May 27 and June 9, 2026.
• Hunt for unauthorized MeshCentral agents and remote management tools.
• Monitor for unusual administrative activity, data access, and large outbound transfers.
• Conduct compromise assessments on exposed PeopleSoft systems.

What FortiGuard Coverage is available?

• FortiGuard IPS: Detects and blocks exploitation attempts targeting Oracle PeopleSoft vulnerabilities. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering: Blocks access to known malicious infrastructure and command-and-control domains.
• FortiGuard AntiVirus and Behavior-Based Detection: Detects Mesh-Central-based payloads and malicious post-exploitation activity.
• FortiEDR and FortiXDR: Identify suspicious remote administration activity, persistence mechanisms, and lateral movement behavior.
• FortiSIEM and FortiAnalyzer: Provide visibility into exploitation attempts and post-compromise activity across the environment.

What is the Vulnerability?

Cisco has disclosed a critical security vulnerability, CVE-2026-20245, affecting Cisco Catalyst SD-WAN Manager and confirmed that it is being actively exploited in the wild. The vulnerability resides in the platform's command-line interface (CLI) and allows an authenticated attacker with netadmin privileges to execute arbitrary commands as root on the underlying operating system.

According to Cisco, successful exploitation has been observed in real-world attacks and has resulted in unauthorized configuration changes being pushed to managed SD-WAN edge devices. At the time of disclosure, Cisco had not released a software fix or workaround and instead provided indicators of compromise and investigation guidance to assist affected organizations.

What is the recommended Mitigation?

• Restrict access to SD-WAN Manager administrative interfaces to trusted management networks.
• Review Cisco-provided indicators of compromise and audit logs for evidence of suspicious file uploads, root-level activity, or unauthorized configuration changes.
• Verify the integrity of SD-WAN edge device configurations and policies.
• Rotate privileged SD-WAN credentials and investigate potential credential exposure.
• Monitor Cisco security advisories and apply updates immediately once a fix becomes available.
• Engage incident response procedures if signs of compromise are identified, as patching alone may not remediate an already compromised environment.

What FortiGuard Coverage is available?

• FortiGuard Antivirus & Behavior Detection: Detects and blocks malicious payloads and abnormal process execution that may result from successful exploitation.
• FortiGuard Incident Response Service: Assists organizations in investigating potential compromise, identifying attacker activity, and supporting remediation efforts.
• FortiGuard Managed Detection and Response (MDR): Provides continuous monitoring and detection of post-exploitation activity, privilege escalation attempts, and unauthorized configuration changes within affected environments.

طراحی سایت : رادکام