Skip to content
Critical RCE Vulnerability Discovered in TACACS+ Protocol

Critical RCE Vulnerability Discovered in TACACS+ Protocol

First seen 25 Sep 2026, 05:22 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 05:56 UTC
  • •TACACS+ vulnerability allows pre-auth RCE attacks.
  • •Exploit can be executed over the internet with minimal packets.
  • •Patches available for Shrubbery Networks version; abandoned fork remains vulnerable.

A significant vulnerability has been identified in the TACACS+ protocol, allowing for pre-authentication remote code execution (RCE) attacks. This 33-year-old protocol, crucial for authentication in networking equipment, is widely used across large enterprises and ISPs. The vulnerability, detailed by Elttam, can be exploited over the internet or local networks, requiring only two packets and the ability to crack weak encryption offline. The affected systems include those using TACACS+ for authentication, which encompasses a vast array of modern networking devices. While patches have been released for the version maintained by Shrubbery Networks, the abandoned fork remains vulnerable. A CVE has been assigned (CVE-2026-87902), and the exploit is currently known to be in the wild, with at least two Chinese cyber-espionage groups reportedly exploiting this vulnerability. The disclosure process took several months, highlighting challenges in getting timely patches for legacy systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-10-06
CVE-2023-45239 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-16
CVE-2023-48643 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48842 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-42542 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-87902 published
A critical vulnerability in TACACS+ was disclosed, allowing for pre-authentication RCE attacks.
News.Risky.Biz
2026-09-23
First public PoC released
Proof-of-concept code for exploiting the TACACS+ vulnerability was made public.
www.elttam.com
Recent
Exploitation confirmed in the wild
At least two Chinese cyber-espionage groups have been observed exploiting the TACACS+ vulnerability.
News.Risky.Biz

More articles in this cluster (2)

Following this threat?

Track Salt Typhoon, TacTap and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed