www.elttam.com Critical RCE Vulnerability Discovered in TACACS+ Protocol
Article Content
- •TACACS+ vulnerability allows pre-auth RCE attacks.
- •Exploit can be executed over the internet with minimal packets.
- •Patches available for Shrubbery Networks version; abandoned fork remains vulnerable.
A significant vulnerability has been identified in the TACACS+ protocol, allowing for pre-authentication remote code execution (RCE) attacks. This 33-year-old protocol, crucial for authentication in networking equipment, is widely used across large enterprises and ISPs. The vulnerability, detailed by Elttam, can be exploited over the internet or local networks, requiring only two packets and the ability to crack weak encryption offline. The affected systems include those using TACACS+ for authentication, which encompasses a vast array of modern networking devices. While patches have been released for the version maintained by Shrubbery Networks, the abandoned fork remains vulnerable. A CVE has been assigned (CVE-2026-87902), and the exploit is currently known to be in the wild, with at least two Chinese cyber-espionage groups reportedly exploiting this vulnerability. The disclosure process took several months, highlighting challenges in getting timely patches for legacy systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Salt Typhoon, TacTap and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…