OTX-6ab61e2ec525754334a6ed2d
info
📛 Threat Title
Major vulnerability found in ancient TACACS+ networking protocol
Description
Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS+, a 33-year-old protocol handling authentication on networking equipment. The protocol, released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers. Attackers can exploit the vulnerability over the internet or local networks with only two packets, leveraging weak encryption. The bug affects both major versions of the protocol, maintained by Shrubbery Networks and a Facebook fork. Patches are available for the Shrubbery version, though no CVE has been assigned. Chinese cyber-espionage groups Salt Typhoon and Fire Ant have exploited TACACS+ in operations targeting telecommunications companies worldwide over the past two years, using it for persistence and lateral movement. Pulse contains 4 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
third-party.com
VT 19 / 91
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
third-party.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | phishing |
| BitDefender | malicious | phishing |
| Chong Lua Dao | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Emsisoft | malicious | malware |
| ESTsecurity | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | phishing |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| LevelBlue | malicious | phishing |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Netcraft | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | phishing |
| VIPRE | malicious | malware |
| Certego | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Network Solutions, LLC |
| TLD | com |
History
| Creation date | 1996-11-24 05:00 UTC |
| Last analysis | 2026-09-25 17:41 UTC |
| Last modified on VirusTotal | 2026-09-25 23:23 UTC |
| Last WHOIS update | 2026-02-05 07:34 UTC |
| WHOIS record date | 2026-09-01 09:43 UTC |
cve
CVE-2026-87902
IOC database
- Type
- cve
- Value
CVE-2026-87902- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- WordPress Core <= 7.1.1 - Unauthenticated Local File Inclusion via locate_template() Path Traversal
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-48842
IOC database
- Type
- cve
- Value
CVE-2026-48842- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-42542
IOC database
- Type
- cve
- Value
CVE-2026-42542- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- reference AlienVaulkt OTX
-
OTX pulse
AlienVaulkt OTX
Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS+, a 33-year-old protocol handling authentication on networking equipment. The protocol, released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers. Attackers can exploit the vulnerability over the internet or local networks with only two packets, leveraging weak encryption. The b
Remediations (8)
-
web:blog.rankiteo.com
A newly disclosed vulnerability in TACACS +, a 33-year-old authentication protocol widely used in enterprise networks, ISPs, and cloud providers, allows attackers to execute pre-authentication remote code execution (RCE) on vulnerable servers. Discovered by Australian security firm Elttam, the flaw enables malicious actors to compromise TACACS+ servers with just two packets, exploiting weak ...
-
web:cybersecuritynews.com
A critical vulnerability in the implementation of the TACACS+ protocol for Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication controls or access sensitive data.
-
web:news.risky.biz
A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS +, a 33-year-old protocol that handles authentication on networking equipment. The protocol — T erminal A ccess C ontroller A ccess- C ontrol S ystem P lus (TACACS+)—was released in 1993 by Cisco as an upgrade for the original TACACS protocol from 1984. It works on ...
-
web:risky.biz
A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS +, a 33-year-old protocol that handles authentication on networking equipment.
-
web:sec.cloudapps.cisco.com
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine- in -the-middle attacker could exploit this ...
-
web:thedailytechfeed.com
Ensure that each TACACS+ server entry includes a shared secret key. If any server lacks an associated key, the device is vulnerable and requires immediate remediation . Mitigation and Remediation Cisco has issued a security advisory detailing the vulnerability and has made fixed software releases available for affected products.
-
web:www.threatclaw.ai
CVE-2025-20160 is a critical vulnerability in the TACACS+ implementation within Cisco IOS and IOS XE software. It allows unauthenticated, remote attackers to perform MitM attacks, leading to sensitive data exposure or complete authentication bypass.
-
web:www.threatops.tech
Technical Description Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS +, a 33-year-old protocol handling authentication on networking equipment. The protocol , released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.