s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

OTX-6ab61e2ec525754334a6ed2d info

📛 Threat Title

Major vulnerability found in ancient TACACS+ networking protocol

Category: Salt Typhoon, Fire Ant Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS+, a 33-year-old protocol handling authentication on networking equipment. The protocol, released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers. Attackers can exploit the vulnerability over the internet or local networks with only two packets, leveraging weak encryption. The bug affects both major versions of the protocol, maintained by Shrubbery Networks and a Facebook fork. Patches are available for the Shrubbery version, though no CVE has been assigned. Chinese cyber-espionage groups Salt Typhoon and Fire Ant have exploited TACACS+ in operations targeting telecommunications companies worldwide over the past two years, using it for persistence and lateral movement. Pulse contains 4 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain third-party.com VT 19 / 91 UrlVoid 3 / 35

IOC database

Type
domain
Value
third-party.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 19 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai malicious phishing
BitDefender malicious phishing
Chong Lua Dao malicious malicious
CRDF malicious malicious
CyRadar malicious malicious
Emsisoft malicious malware
ESTsecurity malicious malicious
Forcepoint ThreatSeeker malicious phishing
Fortinet malicious malware
G-Data malicious phishing
LevelBlue malicious phishing
Lionic malicious malicious
MalwareURL malicious malware
Netcraft malicious malicious
SOCRadar malicious malicious
Sophos malicious phishing
VIPRE malicious malware
Certego suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNetwork Solutions, LLC
TLDcom
History
Creation date1996-11-24 05:00 UTC
Last analysis2026-09-25 17:41 UTC
Last modified on VirusTotal2026-09-25 23:23 UTC
Last WHOIS update2026-02-05 07:34 UTC
WHOIS record date2026-09-01 09:43 UTC
cve CVE-2026-87902

IOC database

Type
cve
Value
CVE-2026-87902
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
WordPress Core <= 7.1.1 - Unauthenticated Local File Inclusion via locate_template() Path Traversal

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-48842

IOC database

Type
cve
Value
CVE-2026-48842
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-42542

IOC database

Type
cve
Value
CVE-2026-42542
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • reference AlienVaulkt OTX
  • OTX pulse AlienVaulkt OTX

    Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS+, a 33-year-old protocol handling authentication on networking equipment. The protocol, released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers. Attackers can exploit the vulnerability over the internet or local networks with only two packets, leveraging weak encryption. The b

Remediations (8)

  • web:blog.rankiteo.com

    A newly disclosed vulnerability in TACACS +, a 33-year-old authentication protocol widely used in enterprise networks, ISPs, and cloud providers, allows attackers to execute pre-authentication remote code execution (RCE) on vulnerable servers. Discovered by Australian security firm Elttam, the flaw enables malicious actors to compromise TACACS+ servers with just two packets, exploiting weak ...

  • web:cybersecuritynews.com

    A critical vulnerability in the implementation of the TACACS+ protocol for Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication controls or access sensitive data.

  • web:news.risky.biz

    A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS +, a 33-year-old protocol that handles authentication on networking equipment. The protocol — T erminal A ccess C ontroller A ccess- C ontrol S ystem P lus (TACACS+)—was released in 1993 by Cisco as an upgrade for the original TACACS protocol from 1984. It works on ...

  • web:risky.biz

    A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS +, a 33-year-old protocol that handles authentication on networking equipment.

  • web:sec.cloudapps.cisco.com

    A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine- in -the-middle attacker could exploit this ...

  • web:thedailytechfeed.com

    Ensure that each TACACS+ server entry includes a shared secret key. If any server lacks an associated key, the device is vulnerable and requires immediate remediation . Mitigation and Remediation Cisco has issued a security advisory detailing the vulnerability and has made fixed software releases available for affected products.

  • web:www.threatclaw.ai

    CVE-2025-20160 is a critical vulnerability in the TACACS+ implementation within Cisco IOS and IOS XE software. It allows unauthenticated, remote attackers to perform MitM attacks, leading to sensitive data exposure or complete authentication bypass.

  • web:www.threatops.tech

    Technical Description Australian security firm Elttam discovered a critical pre-authentication remote code execution vulnerability in TACACS +, a 33-year-old protocol handling authentication on networking equipment. The protocol , released by Cisco in 1993 and now baked into almost all modern networking devices, is widely used at large enterprises, ISPs, data centers, and cloud providers ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.