www.sentinelone.com Cling Botnet Exploits Realtek Jungle SDK Vulnerability
Article Content
- •CVE-2021-35394 is a critical RCE vulnerability in Realtek Jungle SDK.
- •Cling botnet exploits STUN traffic for covert command-and-control operations.
- •Active exploitation attempts began in early September 2026, despite the patch being available.
Threat actors are exploiting a critical vulnerability (CVE-2021-35394) in the Realtek Jungle SDK to deploy a botnet malware named Cling. This malware utilizes STUN traffic to create a covert command-and-control channel, allowing it to blend in with legitimate network activity. The vulnerability, which has a CVSS score of 9.8, affects versions v2.x to v3.4.14B of the SDK, widely used in IoT devices and routers. Exploitation attempts began around September 5, 2026, with the malware embedding exploit logic for multiple other vulnerabilities in routers and DVRs. The Cling botnet can achieve persistence on infected systems by modifying system files and replacing legitimate binaries. As of October 5, 2026, the vulnerability has been patched, but attempts have been observed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Cling and CVE-2014-8361 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected by CVE-2021-35394?
Is the vulnerability still being exploited?
What actions should be taken to mitigate this risk?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…