INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells

| 2026-09-09 20:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 9, 2026, three distinct threat actor clusters were identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. The attackers exploited two vulnerabilities: CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation, while CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. At least six indicators of compromise were reported, including the IP addresses [IOC HIDDEN • LOGIN REQUIRED] and [IOC HIDDEN • LOGIN REQUIRED]. The attackers used various tactics, including authentication bypass, credential theft tools, Cyclops Blink malware, ransomware, reverse shells, and SQL injection vulnerabilities.
Technical Mitigations AI-generated
• Patch Cisco Secure Firewall Management Center (FMC) Software to address CVE-2026-20079 and CVE-2026-20316. • Apply available hotfixes for SonicWall SMA 1000 Appliances to mitigate CVE-2026-83548, CVE-2026-83549, and CVE-2026-9586. • Block or hunt for HTTP request/response smuggling vulnerabilities in Kludex Starlette (CVE-2026-48710) using techniques such as URL rewriting and content filtering.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ho•••••.ai
db•••••.log
176.65.•••.•••
8.4.•••.•••
6f98ad••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b037f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
db4911••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops BlinkQilinQilinAgendaAgenda CVE-2026-24770CVE-2026-24770 CVE-2026-20316CVE-2026-20316 CVE-2026-82329CVE-2026-82329 CVE-2026-48710CVE-2026-48710 CVE-2026-28797CVE-2026-28797 CVE-2026-20079CVE-2026-20079 CVE-2026-49869CVE-2026-49869 CVE-2025-68700CVE-2025-68700 CVE-2026-59822CVE-2026-59822 CVE-2026-9586CVE-2026-9586 CVE-2026-83549CVE-2026-83549 CVE-2026-45312CVE-2026-45312 CVE-2026-42271CVE-2026-42271 CVE-2025-69286CVE-2025-69286 CVE-2026-83548CVE-2026-83548
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/09/09
Threat actors exploited exposed RAGFlow instances using flaws like CVE-2026-45312, CVE-2026-28797, and others to establish persistence and steal large language model provider keys.
organisation Cisco Secure Firewall Management Center
organisation Secure Firewall Management Center
infrastructure 4,000 devices
infrastructure 8.4.0
infrastructure Windows
data_breach 8.3 Switchvox SMB Edition
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
4,000
Devices
Metrics
infrastructure
‎8.4.0
Software Version
Metrics
data_breach
8
Switchvox Smb Edition