๐จ ACTIVE EXPLOITATION
- Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA
Gunra ransomware affiliates are exploiting Fortinet VPN flaws to breach organizations.
- Government, critical infrastructure, healthcare, financial services, manufacturing, transportation, and other sectors are targeted.
- Gunra exploits Fortinet vulnerabilities
CVE-2024-55591andCVE-2025-24472in internet-facing firewall and VPN appliances. - Actors tamper with VPN or VDI authentication files to bypass MFA and gain privileged access.
- Impacket tools support SMB lateral movement, credential dumping, pass-the-hash, and pass-the-ticket attacks.
- Gunra exfiltrates enterprise data before encrypting files with ChaCha20 and RSA-4096, appending .ENCRT and dropping R3ADM3.txt. ๐ Coverage: cryptika.com ยท ๐ via cryptika.com (discovered)
๐ CVEs & KEV
- CVE-2026-72902 โ CVSS 9.9 โ Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / r...
- CVE-2026-72901 โ CVSS 9.9 โ Dokploy: Remote Code Execution via volume-backupDokploy is a free, self-hosta...
- CVE-2026-72886 โ CVSS 9.9 โ Dokploy: Non-admin member gains root on the host by bypassing the owner/admin...
- CVE-2026-72882 โ CVSS 9.9 โ Dokploy: Authenticated blind command injection via file mounts leads to direc...
- CVE-2026-72872 โ CVSS 9.9 โ Dokploy Critical RCE via Unvalidated Bitbucket Configuration (CVE-2026-72872)
- CVE-2025-15681 โ CVSS 9.2 โ Insufficient Webserver AuthenticationTBEA TLogger V2.1.0.0B0.0.0.0 contains a...
- CVE-2025-15683 โ CVSS 8.8 โ Multiple Unauthenticated Denial-of-Service ConditionsTBEA TLogger V2.1.0.0B0....
- CVE-2026-72883 โ CVSS 8.8 โ Dokploy: WebSocket Terminal Missing Service-Level Access ControlDokploy is a ...
- CVE-2026-69118 โ CVSS 8.7 โ Cachet 2.4.1 Authenticated Server-Side Template Injection RCECachet through 2...
- CVE-2025-15682 โ CVSS 8.7 โ Unauthenticated Resource ExhaustionTBEA TLogger V2.1.0.0B0.0.0.0 contains an ...
- CVE-2026-72884 โ CVSS 8.7 โ Dokploy: Command Injection via Compose Custom CommandDokploy is a free, self-...