View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Actively exploited Cisco ASA and FTD flaw can crash firewalls

๐Ÿšจ ACTIVE EXPLOITATION

  • Actively exploited Cisco ASA and FTD flaw can crash firewalls Attackers are exploiting a Cisco firewall flaw to remotely crash devices.

    • Cisco Secure Firewall ASA and FTD customers are affected; Secure Firewall Management Center is not.
    • CVE-2026-20349 affects ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, plus FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.
    • The flaw impacts IKEv2 Remote Access VPN, SSL VPN and FTD Zero Trust Network Access configurations.
    • Unauthenticated attackers send crafted HTTP requests to the Remote Access SSL VPN service.
    • Successful exploitation reloads the firewall and causes a denial-of-service condition; CISA added the flaw to its KEV catalog. ๐Ÿ“Ž Coverage: cybersecuritydive.com ยท ๐Ÿ‘ via Cybersecurity Dive
  • Attackers Weaponize Rapid7 SharePoint Authentication-Bypass PoC CVE-2026-55040 Attackers are exploiting a Microsoft SharePoint authentication-bypass vulnerability using Rapid7's public PoC.

    • Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019 are affected.
    • CVE-2026-55040 enables unauthenticated attackers to bypass JWT authentication.
    • Attackers can impersonate SharePoint users or administrators to disclose files and modify data.
    • Defused observed attacks against its honeypots using Rapid7's PoC shortly after release. ๐Ÿ“„ Source: rapid7.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Colombia's Justice Ministry Hit by Ransomware Before Presidential Transition Ransomware disrupted services at Colombia's Justice Ministry.

    • Colombia's Ministry of Justice was targeted days before the presidential transition.
    • The attack disrupted services supporting illicit-drug monitoring and legal processes.
    • The ministry reported a ransomware attack against its technology infrastructure.
    • Acting Justice Minister Cielo Rusinque denied that information had been stolen. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading
  • Helpjuice support pages reportedly compromised in ClickFix attack Helpjuice-hosted support pages were reportedly altered to deliver a ClickFix lure.

    • Helpjuice-hosted customer support pages were reportedly affected.
    • Visitors saw a fake Cloudflare CAPTCHA page.
    • The lure instructed users to press Windows+R, paste a PowerShell command, and press Enter.
    • Helpjuice reportedly switched its status site to read-only mode after identifying a security incident. ๐Ÿ“Ž Coverage: reddit.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-26035 โ€” CVSS 9.8 โ€” FortiWeb Critical Improper Authentication Bypass (CVE-2026-26035)
  • CVE-2026-50561 โ€” CVSS 9.4 โ€” Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator ...
  • CVE-2026-67285 โ€” CVSS 9.2 โ€” Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file ...
  • CVE-2026-47231 โ€” CVSS 8.1 โ€” Admidio has IDOR in documents-files.php mode=move_save that lets any fold...
  • CVE-2026-49349 โ€” CVSS 6.8 โ€” regclient may leak authentication credentials to external blob storesregclien...
  • CVE-2026-47233 โ€” CVSS 6.5 โ€” Admidio: Any logged-in user can delete inventory fields via `mode=field_delet...
  • CVE-2026-47230 โ€” CVSS 6.5 โ€” Admidio: IDOR in documents-files.php allows cross-folder file rename and desc...
  • CVE-2026-47227 โ€” CVSS 6.5 โ€” Admidio module-administrator can delete or reorder categories owned by other ...
  • CVE-2026-47226 โ€” CVSS 6.5 โ€” Admidio: Authorization bypass in file_delete enables cross-folder file remova...
  • CVE-2026-67287 โ€” CVSS 6.3 โ€” Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Pa...
  • CVE-2026-67286 โ€” CVSS 6.3 โ€” Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creat...
  • CVE-2026-73374 โ€” CVSS 6.1 โ€” Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnera...

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check