WireGuard — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
April 8, 2026
Last Seen
August 13, 2026

Related Threat Clusters

Recent Intelligence Reports

  • Sqlite Wal Reset Bug — tailscale.com · August 13, 2026
  • [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched — Buttondown · August 12, 2026
  • Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals — Cybersecuritynews · August 12, 2026
  • wg-easy wg-easy - OS Command InjectionAn OS command injection vulnerability i... CVE: New / 18h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quic — cve.threatint.com · August 12, 2026
  • CVE-2026-72603 AKAOMA CVE VULNERABILITIES / 18h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients — cve.akaoma.com · August 12, 2026
  • CVE-2026-72603 National Vulnerability Database / 10h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with cl — nvd.nist.gov · August 11, 2026
  • Sandworm hackers target IT pros with trojanized WireGuard VPN client — Bleepingcomputer · August 11, 2026
  • CVE-2026-72603 - Exploits & Severity — Feedly · August 11, 2026

CVSS v3.1 Breakdown