View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Cisco ASA and FTD VPN flaw exploited to crash firewalls

๐Ÿšจ ACTIVE EXPLOITATION

  • Cisco ASA and FTD VPN flaw exploited to crash firewalls CVE-2026-20349 Cisco reports active exploitation of a flaw that crashes ASA and FTD firewalls.

    • Cisco Secure Firewall ASA and Threat Defense (FTD) appliances are affected.
    • CVE-2026-20349 is a heap inspection vulnerability causing denial of service.
    • An unauthenticated remote attacker can exploit the VPN flaw to force devices to reload. ๐Ÿ“„ Source: sec.cloudapps.cisco.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer, @campuscodi@mastodon.social (+1)
  • Metabase CVE-2026-72898 SQL injection exploited in zero-day attacks CVE-2026-72898 Attackers exploited a critical Metabase SQL injection flaw to steal customer data.

    • Metabase Cloud and self-hosted instances on versions 1.58 and later are affected; Framework and Tally reported breaches.
    • CVE-2026-72898 enables unauthenticated SQL injection, administrator access, credential theft, and data exfiltration.
    • Vulnerable branches include 0.58.0โ€“0.58.23, 0.59.0โ€“0.59.20, 0.60.0โ€“0.60.16, 0.61.0โ€“0.61.10, 0.62.0โ€“0.62.8, and 0.63.0โ€“0.63.3.
    • The exploit abuses the unauthenticated /api/session/reset_password endpoint with a crafted user-id value interpreted as raw SQL.
    • Observed attacks showed POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200. ๐Ÿ“„ Source: nvd.nist.gov ยท ๐Ÿ“Ž Coverage: wiz.io ยท ๐Ÿ‘ via CISA KEV

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Zoom annotation flaws enabled zero-click device hijacking during calls Zoom patched annotation flaws that could let meeting participants remotely execute code on other attendees' devices.

    • Zoom users on Windows, macOS, Linux, iOS, and Android were affected.
    • Zoom Workplace clients through versions 7.0.5, plus Rooms and Meeting SDK clients, were vulnerable.
    • CVE-2026-53413 enabled remote code execution through a memory-corruption flaw in the annotation protocol.
    • Attackers could send specially crafted annotation messages that clients automatically parsed without user interaction or visible warning.
    • Fixed versions included Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5. ๐Ÿ“„ Source: zoom.com ยท ๐Ÿ“Ž Coverage: wired.com ยท ๐Ÿ‘ via The Hacker News
  • electerm flaw enables command injection via crafted FTP/SFTP folders CVE-2026-73224 electerm is vulnerable to command injection through crafted FTP/SFTP folder names.

    • electerm versions before 3.15.120 are affected.
    • A malicious FTP or SFTP server can target electerm users with downloaded folders.
    • The vulnerable calcLocal function inserts folder names into a du -sh shell command without escaping single quotes.
    • Execution occurs when a user opens Properties and selects Calculate Size for the crafted folder.
    • CVE-2026-73224 has a CVSS score of 8.8; no public PoC was available. ๐Ÿ“„ Source: undercode.help ยท ๐Ÿ“Ž Coverage: thehackerwire.com ยท ๐Ÿ‘ via thehackerwire.com (discovered)
  • Expired DMARC domain exposed email reports from 86 domains An expired DMARC reporting domain began receiving reports from 86 domains.

    • The reports covered more than 20 organizations, including The Toro Company, universities, school districts, education agencies, counties, and commercial domains.
    • The exposed data came from DMARC aggregate-reporting addresses configured with gca-emailauth[.]org.
    • The domain had been published in Global Cyber Alliance DMARC training documents since at least 2019 before expiring.
    • A researcher registered gca-emailauth[.]org for $10 and received reports from 86 domains, including 56 associated with The Toro Company.
    • The Toro Company's myturf[.]com distributor platform was among the domains and used a DMARC policy of p=none. ๐Ÿ“„ Source: reddit.com ยท ๐Ÿ“Ž Coverage: sh.consulting ยท ๐Ÿ‘ via r/netsec
  • Sub2API path traversal lets tenants relay requests through pooled credentials CVE-2026-73079 Sub2API has a high-severity path traversal vulnerability.

    • Sub2API AI API gateway deployments and their authenticated tenants are affected.
    • Versions 0.1.135 through 0.1.168 are vulnerable to CVE-2026-73079.
    • A tenant with a valid platform API key can target arbitrary upstream endpoints.
    • The flaw affects POST /responses/*subpath routes that splice client input into upstream URLs.
    • Requests use the operator's pooled provider credentials; CVSS 8.5. ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: thehackerwire.com ยท ๐Ÿ‘ via thehackerwire.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-48804 โ€” CVSS 7.5 โ€” python-socketio: Binary attachment accumulation can cause denial of servicepy...
  • CVE-2026-18712 โ€” CVSS 7.2 โ€” Improper Authorization in MongoDB Queryable Encryption Maintenance Operations...
  • CVE-2026-18711 โ€” CVSS 7.1 โ€” Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service a...
  • CVE-2026-68872 โ€” CVSS 6.5 โ€” Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-s...
  • CVE-2026-71474 โ€” CVSS 6.3 โ€” Insights-client-rhel9: insights-client: pull-secret bearer token written to l...

๐Ÿ“‹ ADVISORIES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check