Skip to content
Emerging Threats from CVE-2022-26809 and CVE-2023-34362 Exploits

Emerging Threats from CVE-2022-26809 and CVE-2023-34362 Exploits

First seen 28 Sep 2026, 10:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 10:10 UTC

Recent reports highlight two significant vulnerabilities: CVE-2022-26809 and CVE-2023-34362. CVE-2022-26809, published on April 15, 2022, involves a trap targeting red team operators using mobile hotspots, potentially exposing their phone numbers. The exploit is designed to evade detection when debugging tools are active. Meanwhile, CVE-2023-34362, published on June 2, 2023, affects MOVEit Transfer and allows attackers to exploit SQL injection to gain unauthorized access to admin API tokens, leading to remote code execution. The proof-of-concept for CVE-2023-34362 was made public on June 7, 2023, and it is actively exploited in the wild. Security professionals are advised to remain vigilant and apply necessary patches to mitigate these threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2022-04-15
CVE-2022-26809 published
CVE-2022-26809 disclosed, targeting mobile hotspots to track red team operators.
Sploitus
2023-06-02
CVE-2023-34362 published
CVE-2023-34362 disclosed, affecting MOVEit Transfer with SQL injection capabilities.
Sploitus
2023-06-07
Public PoC for CVE-2023-34362 released
Proof-of-concept code for CVE-2023-34362 made publicly available, demonstrating exploitation techniques.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2022-26809 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed