[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/recent-exploits-network-security-trends/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/ "Trend Reports")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Yue Guan](https://unit42.paloaltonetworks.com/author/yue-guan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 19, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/)
  * [CVE-2021-20166](https://unit42.paloaltonetworks.com/tag/cve-2021-20166/)
  * [CVE-2021-20167](https://unit42.paloaltonetworks.com/tag/cve-2021-20167/)
  * [CVE-2021-21881](https://unit42.paloaltonetworks.com/tag/cve-2021-21881/)
  * [CVE-2021-24762](https://unit42.paloaltonetworks.com/tag/cve-2021-24762/)
  * [CVE-2021-28169](https://unit42.paloaltonetworks.com/tag/cve-2021-28169/)
  * [CVE-2021-31589](https://unit42.paloaltonetworks.com/tag/cve-2021-31589/)
  * [CVE-2021-39226](https://unit42.paloaltonetworks.com/tag/cve-2021-39226/)
  * [CVE-2021-4045](https://unit42.paloaltonetworks.com/tag/cve-2021-4045/)
  * [CVE-2021-43711](https://unit42.paloaltonetworks.com/tag/cve-2021-43711/)
  * [CVE-2022-21371](https://unit42.paloaltonetworks.com/tag/cve-2022-21371/)
  * [CVE-2022-21662](https://unit42.paloaltonetworks.com/tag/cve-2022-21662/)
  * [CVE-2022-22536](https://unit42.paloaltonetworks.com/tag/cve-2022-22536/)
  * [CVE-2022-22947](https://unit42.paloaltonetworks.com/tag/cve-2022-22947/)
  * [CVE-2022-22954](https://unit42.paloaltonetworks.com/tag/cve-2022-22954/)
  * [CVE-2022-22963](https://unit42.paloaltonetworks.com/tag/cve-2022-22963/)
  * [CVE-2022-22965](https://unit42.paloaltonetworks.com/tag/cve-2022-22965/)
  * [CVE-2022-24112](https://unit42.paloaltonetworks.com/tag/cve-2022-24112/)
  * [CVE-2022-24260](https://unit42.paloaltonetworks.com/tag/cve-2022-24260/)
  * [CVE-2022-25060](https://unit42.paloaltonetworks.com/tag/cve-2022-25060/)
  * [CVE-2022-25075](https://unit42.paloaltonetworks.com/tag/cve-2022-25075/)
  * [CVE-2022-25134](https://unit42.paloaltonetworks.com/tag/cve-2022-25134/)
  * [CVE-2022-27226](https://unit42.paloaltonetworks.com/tag/cve-2022-27226/)
  * [CVE-2022-29464](https://unit42.paloaltonetworks.com/tag/cve-2022-29464/)
  * [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/)
  * [Network security trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Network%20Security%20Trends:%20Recent%20Exploits%20Observed%20in%20the%20Wild%20Include%20Remote%20Code%20Execution,%20Cross-Site%20Scripting%20and%20More&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F&title=Network%20Security%20Trends:%20Recent%20Exploits%20Observed%20in%20the%20Wild%20Include%20Remote%20Code%20Execution,%20Cross-Site%20Scripting%20and%20More "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F&text=Network%20Security%20Trends:%20Recent%20Exploits%20Observed%20in%20the%20Wild%20Include%20Remote%20Code%20Execution,%20Cross-Site%20Scripting%20and%20More "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Network%20Security%20Trends:%20Recent%20Exploits%20Observed%20in%20the%20Wild%20Include%20Remote%20Code%20Execution,%20Cross-Site%20Scripting%20and%20More%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frecent-exploits-network-security-trends%2F "Share in Mastodon")

## **Executive Summary**

Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.

Other insights that could assist defenders include our rankings of the most commonly used techniques and the types of vulnerabilities that attackers have recently favored. For example, among 6,000 newly published vulnerabilities, a large portion (almost 13.3%) involve cross-site scripting, suggesting that defenders may wish to consider how best to mitigate this technique across internet-facing properties.

Other major focuses identified by evaluating more than 93 million attack sessions include remote code execution, traversal and information disclosure.

Additionally, we provide insight into how these vulnerabilities are actively exploited in the wild based on real-world data collected from [Palo Alto Networks Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall). For example, we highlight how frequently the most commonly exploited vulnerabilities were attacked through networks and the locations from which the attacks appeared to originate. We then draw conclusions about the most commonly exploited vulnerabilities attackers are using, as well as the severity, category and origin of each attack.

Here, we summarize key trends from February-April 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, say, cross-site scripting or denial-of-service.

Palo Alto Networks customers receive protections from the vulnerabilities discussed here through the [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) and [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention), [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), as well as through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr).

|----------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CVEs Discussed                               | [CVE-2022-22954](https://nvd.nist.gov/vuln/detail/CVE-2022-22954), [CVE-2022-22963](https://nvd.nist.gov/vuln/detail/CVE-2022-22963), [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965), [CVE-2022-25060](https://nvd.nist.gov/vuln/detail/CVE-2022-25060), [CVE-2022-22947](https://nvd.nist.gov/vuln/detail/CVE-2022-22947), [CVE-2022-24112](https://nvd.nist.gov/vuln/detail/CVE-2022-24112), [CVE-2022-22536](https://nvd.nist.gov/vuln/detail/CVE-2022-22536), [CVE-2021-24762](https://nvd.nist.gov/vuln/detail/CVE-2021-24762), [CVE-2022-21662](https://nvd.nist.gov/vuln/detail/CVE-2022-21662), [CVE-2021-43711](https://nvd.nist.gov/vuln/detail/CVE-2021-43711), [CVE-2022-25075](https://nvd.nist.gov/vuln/detail/CVE-2022-25075), [CVE-2022-25134](https://nvd.nist.gov/vuln/detail/CVE-2022-25134), [CVE-2021-4045](https://nvd.nist.gov/vuln/detail/CVE-2021-4045), [CVE-2022-24260](https://nvd.nist.gov/vuln/detail/CVE-2022-24260), [CVE-2021-21881](https://nvd.nist.gov/vuln/detail/CVE-2021-21881), [CVE-2021-39226](https://nvd.nist.gov/vuln/detail/CVE-2021-39226), [CVE-2021-28169](https://nvd.nist.gov/vuln/detail/CVE-2021-28169), [CVE-2021-20167](https://nvd.nist.gov/vuln/detail/CVE-2021-20167), [CVE-2021-20166](https://nvd.nist.gov/vuln/detail/CVE-2021-20166), [CVE-2022-21371](https://nvd.nist.gov/vuln/detail/CVE-2022-21371), [CVE-2021-31589](https://nvd.nist.gov/vuln/detail/CVE-2021-31589), [CVE-2022-29464](https://nvd.nist.gov/vuln/detail/CVE-2022-29464), [CVE-2022-27226](https://nvd.nist.gov/vuln/detail/CVE-2022-27226) |
| Types of Attacks and Vulnerabilities Covered | Cross-site scripting, denial of service, information disclosure, buffer overflow, privilege escalation, memory corruption, code execution, SQL injection, out-of-bounds read, cross-site request forgery, directory traversal, command injection, improper authentication, security feature bypass                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Related Unit 42 Topics                       | [Network Security Trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/), [exploits in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/), [attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

*Updated Sept. 2 at 12:30 p.m. PT to remove two CVEs that were listed in error.*

## **Analysis of Published Vulnerabilities, February 2022 to April 2022**

From February-April 2022, a total of 5,962 new Common Vulnerabilities and Exposures (CVE) numbers were registered. To better understand the potential impact these newly published vulnerabilities could have on network security, we provide our observations based on the severity, proof-of-concept code feasibility and vulnerability categories.

### **How Severe Are the Latest Vulnerabilities?**

To estimate the potential impact of vulnerabilities, we consider their severity and examine any reliable proofs of concept (PoCs) available that attackers could easily launch. Some of the public sources we use to find PoCs are Exploit-DB, GitHub and Metasploit. Distribution of the 5,631 CVEs that have an assigned severity score of medium or higher can be seen in the following table:

|--------------|-----------|-----------|----------------------|
| **Severity** | **Count** | **Ratio** | **PoC Availability** |
| Critical     | 1033      | 18.3%     | 7.8%                 |
| High         | 2282      | 40.5%     | 4.8%                 |
| Medium       | 2316      | 41.1%     | 3.6%                 |

*Table 1. Severity distribution for CVEs registered February-April 2022.*
![Medium severity: 41.1%, high severity: 40.5%, critical severity: 18.3%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-13.png) Figure 1. Severity distribution for CVEs registered from February-April 2022, including only those rated medium-critical.

Vulnerabilities classified as critical are the least common but are also more likely to have PoCs available. The data suggests a correlation between the availability of a PoC and the severity of a vulnerability. In the period discussed, the critical-severity ratios increased while high-severity and medium-severity PoC ratios decreased slightly. Palo Alto Networks continues to leverage threat intelligence of the latest vulnerabilities and real-time monitoring of exploits in the wild to provide protections for our customers.

### **Vulnerability Category Distribution**

The type of vulnerability is also crucial to understanding its consequences. Out of the newly published CVEs that were analyzed, 26.4% are classified as local vulnerabilities, requiring prior access to compromised systems, while the remaining 73.6% are remote vulnerabilities, which can be exploited over a network. This means that the majority of newly published vulnerabilities introduce potential opportunities for threat actors to attack vulnerable organizations from anywhere in the world.

As shown in Figure 2, we can see the most common vulnerability types ranked by how prevalent they were among the most recent set of published vulnerabilities.
![Red = critical, yellow = high, blue = medium. In order from most to least prevalent vulnerability category: cross-site scripting, out-of-bounds write, information disclosure, SQL injection, privilege escalation, denail of service, command injection, file related, traversal, remote code execution, improper authentication, improper input validation, buffer overflow](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-14.png) Figure 2. Vulnerability category distribution for CVEs registered February 2022-April 2022.

Cross-site scripting remains the most reported vulnerability in this time period, and we also saw an increase in out-of-bounds write and information disclosure vulnerabilities published compared to last quarter. However, most of the recently published cross-site scripting and information disclosure attacks are usually at medium or high severity (rather than critical). At the same time, the prevalence of SQL injection vulnerabilities increased in February-April 2022 -- and many of the vulnerabilities in this category are critical.

## **Network Security Trends: Analysis of Exploits in the Wild, February-April 2022**

### **Data Collection**

By leveraging Palo Alto Networks Next-Generation Firewalls as sensors on the perimeter, Unit 42 researchers observed malicious activities from February-April 2022. The malicious traffic we identified is further processed and based on metrics such as IP addresses, port numbers and timestamps. This ensures the uniqueness of each attack session and thus eliminates potential data skews. We analyzed 93 million valid malicious sessions and then correlated the refined data with other attributes to infer attack trends over time to get a picture of the threat landscape.

### **How Severe Were the Attacks Exploited in the Wild?**

To arrive at 93 million valid malicious sessions, we excluded the original set of low-severity signature triggers that are used to detect scanning and brute-force attacks, as well as internal triggers used for research purposes. Therefore, we consider exploitable vulnerabilities with a severity ranking of medium and higher (based on the [CVSS v3 Score](https://nvd.nist.gov/vuln-metrics/cvss)) as a verified attack.
![Medium severity: 31.3%, high severity: 29.6%, critical severity: 39.1%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-15.png) Figure 3. Attack severity distribution, February-April 2022, including only medium-critical vulnerabilities.

Figure 3 shows the session count and ratio of attacks grouped by the severity of each vulnerability. Compared with the previous quarters' severity distribution, this quarter shows almost no difference for critical-, high- and medium-severity attacks. However, we still focus more on critical-severity attacks because of their greater potential impact. Many published vulnerabilities are scored medium severity, but attackers typically leverage more severe vulnerabilities for exploits. Defenders should pay attention to preventing and mitigating high- and critical-severity network attacks.

### **When Did the Network Attacks Occur?**

![Red = critical, yellow = high, blue = medium, green = total. The bar graph shows attack severity distribution by millions of sessions divided weekly between February-April 2022.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-16.png) Figure 4. Attack severity distribution measured weekly from February-April 2022.

For this installment of our network security trends analysis, we collected data from February-April 2022. Attackers steadily leveraged high-severity exploits throughout this period.

As we've seen in the past, attackers frequently used vulnerabilities disclosed recently, especially those from 2021-22. This shows the importance of updating security products and applying software patches as soon as they become available to protect against the most recently discovered vulnerabilities.
![Red = CVEs disclosed 2021-2022, yellow = CVEs disclosed 2019-2020, blue = CVEs disclosed 2016-2018, green = CVEs disclosed 2010-2015, orange = CVEs disclosed prior to 2010. The bar graph shows attack severity distribution by millions of sessions divided weekly between February-April 2022.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-17.png) Figure 5. Observed attacks broken down by the year in which the exploited CVE was disclosed, measured weekly from February-April 2022.

## **Exploits in the Wild, February-April 2022: A Detailed View**

Among the latest published attacks, the following exploits stood out due to their PoC availability, severity and ease of exploitation. We have provided snippets showing how attackers used open source tools to compromise the different targets, allowing defenders to better understand how the exploit operates.

[CVE-2022-22954](https://nvd.nist.gov/vuln/detail/CVE-2022-22954)

VMware Workspace ONE Access and Identity Manager contain a remote code execution (RCE) vulnerability due to server-side template injection. A malicious actor can trigger a server-side template injection.
![Snippet illustrating the VMware server-side template injection remote code execution vulnerability, CVE-2022-22954.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-58.png) Figure 6. VMware server-side template injection remote code execution vulnerability.

[CVE-2022-22963](https://nvd.nist.gov/vuln/detail/CVE-2022-22963)

In Spring Cloud Function, when using routing functionality, it is possible for a user to provide a specially crafted SpEL as a routing expression that may result in remote code execution and access to local resources.
![Snippet illustrating the Spring Cloud SpEL remote code execution vulnerability, CVE-2022-22963.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-59.png) Figure 7. Spring Cloud SpEL remote code execution vulnerability.

[CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965)

A Spring MVC or Spring WebFlux application may be vulnerable to RCE via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment.
![Snippet illustrating the Spring Core remote code execution vulnerability, CVE-2022-22965.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-60.png) Figure 8. Spring Core remote code execution vulnerability.

[CVE-2022-25060](https://nvd.nist.gov/vuln/detail/CVE-2022-25060)

TP-LINK was discovered to contain a command injection vulnerability via the component oal\_startPing.
![Snippet illustrating the TP-LINK command injection vulnerability, CVE-2022-25060.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-61.png) Figure 9. TP-LINK command injection vulnerability.

[CVE-2022-22947](https://nvd.nist.gov/vuln/detail/CVE-2022-22947)

In Spring Cloud Gateway, applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker can craft a malicious request that would allow arbitrary remote execution on the remote host.
![Snippet illustrating the Spring Cloud Gateway code injection vulnerability, CVE-2022-22947.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-62.png) Figure 10. Spring Cloud Gateway code injection vulnerability.

[CVE-2022-24112](https://nvd.nist.gov/vuln/detail/CVE-2022-24112)

An attacker can abuse the batch requests plugin to send requests and bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to RCE.
![Snippet illustrating the Apache APISIX remote code execution vulnerability, CVE-2022-24112.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-63.png) Figure 11. Apache APISIX remote code execution vulnerability.

[CVE-2022-22536](https://nvd.nist.gov/vuln/detail/CVE-2022-22536)

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request using arbitrary data.
![Snippet illustrating the SAP multiple products HTTP request smuggling vulnerability, CVE-2022-22536.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-64.png) Figure 12. SAP multiple products HTTP request smuggling vulnerability.

[CVE-2021-24762](https://nvd.nist.gov/vuln/detail/CVE-2021-24762)

The Perfect Survey WordPress plugin does not validate and escape the question\_id GET parameter before using it in a SQL statement in the get\_question AJAX action, allowing unauthenticated users to perform SQL injection.
![Snippet illustrating the WordPress Perfect Survey plugin SQL injection vulnerability, CVE-2021-24762.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-65.png) Figure 13. WordPress Perfect Survey plugin SQL injection vulnerability.

[CVE-2022-21662](https://nvd.nist.gov/vuln/detail/CVE-2022-21662)

Low-privileged authenticated users in WordPress core are able to execute JavaScript/perform stored cross-site scripting attacks, which can affect high-privileged users.
![Snippet illustrating the WordPress core post slug stored cross-site scripting vulnerability, CVE-2022-21662.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-66.png) Figure 14. WordPress core post slug stored cross-site scripting vulnerability.

[CVE-2021-43711](https://nvd.nist.gov/vuln/detail/CVE-2021-43711), [CVE-2022-25075](https://nvd.nist.gov/vuln/detail/CVE-2022-25075)

The downloadFlile.cgi binary file in TOTOLINK has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
![Snippet illustrating the TOTOLINK EX200 command injection vulnerabilities, CVE-2021-43711 and CVE-2022-25075.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-67.png) Figure 15. TOTOLINK EX200 command injection vulnerability.

[CVE-2022-25134](https://nvd.nist.gov/vuln/detail/CVE-2022-25134)

A command injection vulnerability in the function setUpgradeFW of the TOTOLINK Technology router allows attackers to execute arbitrary commands.
![Snippet illustrating the TOTOLINK command injection vulnerability, CVE-2022-25134.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-68.png) Figure 16. TOTOLINK command injection vulnerability.

[CVE-2021-4045](https://nvd.nist.gov/vuln/detail/CVE-2021-4045)

TP-Link Tapo C200 IP camera is affected by an unauthenticated RCE vulnerability, which is present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
![Snippet illustrating the TP-Link Tapo C200 remote code execution vulnerability, CVE-2021-4045.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-69.png) Figure 17. TP-Link Tapo C200 remote code execution vulnerability.

[CVE-2022-24260](https://nvd.nist.gov/vuln/detail/CVE-2022-24260)

A SQL injection vulnerability in VoIPmonitor GUI allows an attacker to escalate privileges to the Administrator level.
![Snippet illustrating the VoIPmonitor GUI SQL injection vulnerability, CVE-2022-24260.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-70.png) Figure 18. VoIPmonitor GUI SQL injection vulnerability.

[CVE-2021-21881](https://nvd.nist.gov/vuln/detail/CVE-2021-21881)

An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave. A specially crafted HTTP request can lead to command execution. An attacker can then make an authenticated HTTP request to trigger this vulnerability.
![Snippet illustrating the Lantronix PremierWave 2050 command injection vulnerability, CVE-2021-21881.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-71.png) Figure 19. Lantronix PremierWave 2050 command injection vulnerability.

[CVE-2022-21371](https://nvd.nist.gov/vuln/detail/CVE-2022-21371)

There is an easily exploitable vulnerability in the Oracle WebLogic Server that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
![Snippet illustrating the Oracle Weblogic Server local file inclusion vulnerability, CVE-2022-21371.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-72.png) Figure 20. Oracle Weblogic Server local file inclusion vulnerability.

[CVE-2022-27226](https://nvd.nist.gov/vuln/detail/CVE-2022-27226)

A cross-site request forgery (CSRF) issue in /api/crontab on iRZ Mobile Routers allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to RCE and allowing the threat actor to gain file system access.
![Snippet illustrating the iRZ Mobile Routers cross-site request forgery vulnerability, CVE-2022-27226.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-73.png) Figure 21. iRZ Mobile Routers cross-site request forgery vulnerability.

[CVE-2022-29464](https://nvd.nist.gov/vuln/detail/CVE-2022-29464)

Certain WSO2 products allow unrestricted file upload with resultant RCE. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory.
![Snippet illustrating the WSO2 products arbitrary file upload vulnerability, CVE-2022-29464,](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-74.png) Figure 22. WSO2 products arbitrary file upload vulnerability.

Other active CVEs we observed this quarter:

* [CVE-2021-20167](https://nvd.nist.gov/vuln/detail/CVE-2021-20167), [CVE-2021-20166](https://nvd.nist.gov/vuln/detail/CVE-2021-20166) -- Netgear RAX43 command injection vulnerabilities.
* [CVE-2021-39226](https://nvd.nist.gov/vuln/detail/CVE-2021-39226) -- Grafana Labs Grafana Snapshot authentication bypass vulnerability.
* [CVE-2021-28169](https://nvd.nist.gov/vuln/detail/CVE-2021-28169) -- Eclipse Jetty information disclosure vulnerability.
* [CVE-2021-31589](https://nvd.nist.gov/vuln/detail/CVE-2021-31589) -- BeyondTrust remote support cross-site scripting vulnerability.

### Attack Category Distribution

We classified each network attack by category and organized them in terms of prevalence. In the period discussed, RCE ranks first, followed by traversal attacks. Attackers typically want to gain as much information and control as possible over the systems they target. Information disclosure attacks decreased this quarter.
![Red = critical, yellow = high, blue = medium. Attack categories in order of prevalence: remote code execution, traversal, information disclosure, cross-site scripting, SQL injection, memory corruption, improper authentication, command injection, buffer overflow, privilege escalation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-18.png) Figure 23. Attack category distribution, February-April 2022.

### Where Did the Attacks Originate?

After identifying the region from which each network attack originated, we discovered that the majority of them seem to originate from the United States, followed by Germany and Russia. However, we recognize that the attackers might leverage proxy servers and VPNs located in those countries to hide their actual physical locations.
![Locations ranked in terms of how frequently they were the origin of observed attacks from February-April 2022. United States: 74.1%, Germany: 4.2%, Russian Federation 2.8%, Ireland 1.6%, Netherlands 1.5%, France 1.4%, China 1.3%, Canada 1.1%, Others: 11.1%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-19.png) Figure 24. Locations ranked in terms of how frequently they were the origin of observed attacks from February-April 2022. ![Heat map showing where attacks appear to originate. The United States is deepest red, followed by Germany and Russia.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-20.png) Figure 25. Attack geolocation distribution from February-April 2022.

## **Conclusion**

The vulnerabilities disclosed from February-April 2022 indicate that web applications remain popular targets for attackers, and that critical vulnerabilities are more likely to have PoCs publicly available. In the meantime, we continue to capture newly published vulnerabilities that are exploited in the wild. This emphasizes the need for organizations to promptly patch their systems and implement security best practices. If not, attackers will continue to make a concerted effort to expand their arsenal of exploits whenever possible.

While cybercriminals will never cease their malicious activities, Palo Alto Networks customers receive protections from the attacks discussed in this blog through the [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) and [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention), [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), as well as through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr).

To further mitigate any risks to your network:

* Run a [Best Practice Assessment](https://www.paloaltonetworks.com/services/bpa) to identify where your configuration could be altered to improve your security posture.
* Run a [Security Lifecycle Review](https://docs.paloaltonetworks.com/cortex/security-lifecycle-review/security-lifecycle-review-getting-started) to get a consolidated view of your largest threats and if you have coverage to prevent them.
* Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) content (e.g. versions 8607 and above).

## **Additional Resources**

* [Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report](https://unit42.paloaltonetworks.com/network-threat-trends-research-report/)
* [Network Security Trends: November 2021 to January 2022](https://unit42.paloaltonetworks.com/network-security-trends-cross-site-scripting/)
* [Network Security Trends: August-October 2021](https://unit42.paloaltonetworks.com/network-attacks-trends-august-october-2021/)
* [Network Security Trends: May-July 2021](https://unit42.paloaltonetworks.com/network-security-trends/)
* [Network Attack Trends: February-April 2021](https://unit42.paloaltonetworks.com/network-attack-trends-february-april-2021/)

*Updated Sept. 2 at 12:30 p.m. PT to remove a CVE that was listed in error.*
Back to top

### Tags

* [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/ "attack analysis")
* [CVE-2021-20166](https://unit42.paloaltonetworks.com/tag/cve-2021-20166/ "CVE-2021-20166")
* [CVE-2021-20167](https://unit42.paloaltonetworks.com/tag/cve-2021-20167/ "CVE-2021-20167")
* [CVE-2021-21881](https://unit42.paloaltonetworks.com/tag/cve-2021-21881/ "CVE-2021-21881")
* [CVE-2021-24762](https://unit42.paloaltonetworks.com/tag/cve-2021-24762/ "CVE-2021-24762")
* [CVE-2021-28169](https://unit42.paloaltonetworks.com/tag/cve-2021-28169/ "CVE-2021-28169")
* [CVE-2021-31589](https://unit42.paloaltonetworks.com/tag/cve-2021-31589/ "CVE-2021-31589")
* [CVE-2021-39226](https://unit42.paloaltonetworks.com/tag/cve-2021-39226/ "CVE-2021-39226")
* [CVE-2021-4045](https://unit42.paloaltonetworks.com/tag/cve-2021-4045/ "CVE-2021-4045")
* [CVE-2021-43711](https://unit42.paloaltonetworks.com/tag/cve-2021-43711/ "CVE-2021-43711")
* [CVE-2022-21371](https://unit42.paloaltonetworks.com/tag/cve-2022-21371/ "CVE-2022-21371")
* [CVE-2022-21662](https://unit42.paloaltonetworks.com/tag/cve-2022-21662/ "CVE-2022-21662")
* [CVE-2022-22536](https://unit42.paloaltonetworks.com/tag/cve-2022-22536/ "CVE-2022-22536")
* [CVE-2022-22947](https://unit42.paloaltonetworks.com/tag/cve-2022-22947/ "CVE-2022-22947")
* [CVE-2022-22954](https://unit42.paloaltonetworks.com/tag/cve-2022-22954/ "CVE-2022-22954")
* [CVE-2022-22963](https://unit42.paloaltonetworks.com/tag/cve-2022-22963/ "CVE-2022-22963")
* [CVE-2022-22965](https://unit42.paloaltonetworks.com/tag/cve-2022-22965/ "CVE-2022-22965")
* [CVE-2022-24112](https://unit42.paloaltonetworks.com/tag/cve-2022-24112/ "CVE-2022-24112")
* [CVE-2022-24260](https://unit42.paloaltonetworks.com/tag/cve-2022-24260/ "CVE-2022-24260")
* [CVE-2022-25060](https://unit42.paloaltonetworks.com/tag/cve-2022-25060/ "CVE-2022-25060")
* [CVE-2022-25075](https://unit42.paloaltonetworks.com/tag/cve-2022-25075/ "CVE-2022-25075")
* [CVE-2022-25134](https://unit42.paloaltonetworks.com/tag/cve-2022-25134/ "CVE-2022-25134")
* [CVE-2022-27226](https://unit42.paloaltonetworks.com/tag/cve-2022-27226/ "CVE-2022-27226")
* [CVE-2022-29464](https://unit42.paloaltonetworks.com/tag/cve-2022-29464/ "CVE-2022-29464")
* [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/ "exploit in the wild")
* [Network security trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/ "network security trends")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: BlueSky Ransomware: Fast Encryption via Multithreading](https://unit42.paloaltonetworks.com/bluesky-ransomware/ "BlueSky Ransomware: Fast Encryption via Multithreading")

### Table of Contents

* 

### Related Articles

* [Network Security Trends: November 2022-January 2023](https://unit42.paloaltonetworks.com/network-security-trends-nov-jan/ "article - table of contents")
* [Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain Threats](https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/ "article - table of contents")
* [Network Security Trends: August-October 2022](https://unit42.paloaltonetworks.com/network-security-trends-aug-oct-2022/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
