Skip to content

CVE-2023-26360

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 29, 2026
Last Seen
July 2, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a defense-impairment script (i.bat) that disabled logging and security services. Initial forensic...

Rapid7 disclosed an access control bypass vulnerability in Adobe ColdFusion, identified as CVE-2023-29298, which affects versions 2018u16, 2021u6, and 2023. The vulnerability allows attackers to access restricted administration endpoints by manipulating URL requests. This flaw undermines the securit...

Public Exploits

Checking GitHub for proof-of-concept code…