Skip to content
Multiple CVEs Exploited in Cyber Attacks on Cyber Cafe Software

Multiple CVEs Exploited in Cyber Attacks on Cyber Cafe Software

First seen 22 Sep 2026, 14:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 14:26 UTC
  • CVE-2020-1472 allows DCSync attacks on domain controllers.
  • CVE-2022-48474 and CVE-2022-48475 enable DoS attacks on 'Control de Ciber' software.
  • Exploitation tools for these vulnerabilities are publicly available on GitHub.

Recent reports highlight the exploitation of CVE-2020-1472 and CVE-2022-48474/CVE-2022-48475 vulnerabilities. CVE-2020-1472, affecting domain controllers, allows attackers to perform DCSync operations, potentially compromising entire networks. CVE-2022-48474 and CVE-2022-48475 are DoS vulnerabilities in 'Control de Ciber' software, impacting versions up to 1.650, allowing unauthenticated remote attackers to crash services. The tools for exploiting these vulnerabilities are available on GitHub, increasing the risk of widespread attacks. Organizations using affected systems should prioritize patching and monitoring for unusual activity. The situation remains critical as both vulnerabilities are actively being exploited.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2020-08-17
CVE-2020-1472 published
CVE-2020-1472 was published, affecting domain controllers and enabling DCSync attacks.
Sploitus
2021-11-03
CVE-2020-1472 added to CISA KEV
CISA added CVE-2020-1472 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Sploitus
2023-04-19
First public PoC for CVE-2022-48474
The first proof-of-concept for CVE-2022-48474 was released, demonstrating its exploitation potential.
Sploitus
2023-09-12
CVE-2022-48474 and CVE-2022-48475 published
CVE-2022-48474 and CVE-2022-48475 were published, affecting 'Control de Ciber' software.
Sploitus
Recent
Exploitation tools available
Exploitation tools for CVE-2020-1472 and CVE-2022-48474/CVE-2022-48475 are now available on GitHub, increasing risk.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2020-1472 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed