
Arista patched a maximum-severity, unauthenticated OS command injection in VeloCloud Orchestrator (CVE-2026-16812), while Cisco disclosed an actively exploited zero-day rooted in static, built-in credentials in Secure Firewall Management Center (CVE-2026-20316).
TA488 ran an email campaign exploiting CVE-2026-42897 to deploy the disk-free OWAReaper backdoor. Cl0p-affiliated operators chained a FlexPLM WSDL disclosure with a Windchill login-servlet flaw (CVE-2026-12569) for unauthenticated RCE against internet-exposed PTC deployments.
Weekly Highlights
CVE-2026-20316 turns static, built-in credentials into an actively exploited zero-day.CVE-2026-16812 opened privileged internal functions of Arista's VCO to anyone remotely.CVE-2026-16723 gets RCE straight out of FastJson's default settings, already exploited in the wild.CVE-2026-12569.CVE-2026-42897 turns a glance at Outlook Web Access into OWAReaper, a backdoor that never touches disk.Threat Distribution: Backdoor, Botnet.
Geography
Targeting spanned 99 further countries across Europe, the Americas, Asia, and Africa; the full breakdown is available on the Uni5Xposure platform.
Adversary Tradecraft
| TTP | Tactic | Technique |
|---|---|---|
T1190 |
Initial Access | Exploit Public-Facing Application |
T1059 |
Execution | Command and Scripting Interpreter |
T1068 |
Privilege Escalation | Exploitation for Privilege Escalation |
T1078 |
Defense Evasion | Valid Accounts |
T1588 |
Resource Development | Obtain Capabilities |
T1027 |
Defense Evasion | Obfuscated Files or Information |
T1505.003 |
Persistence | Web Shell |
T1041 |
Exfiltration | Exfiltration Over C2 Channel |
20 TTPs were mapped this week; the full ATT&CK matrix is available to Uni5 customers via Uni5Xposure.
Malware & Campaigns
OWAReaper is a half-click backdoor and evolution of ZimReaper, running entirely inside the Outlook Web Access reading pane to rewrite the malicious email and harvest saved OWA credentials via Outlook APIs. It persists as an encrypted copy in the browser's localStorage under a legitimate OWA settings key, executing automatically whenever OWA is opened.
CVE-2026-428976897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4asecdns[.]com, acocdn[.]com, dnsrecursive[.]eu, tdndns[.]comTengu is a Linux botnet derived from Mirai but more advanced in stealth and self-preservation, spreading via Telnet credential brute force across IoT and embedded Linux devices on multiple processor architectures.
897226af37990fa60f25fea00b0509faa0e78d8bee10875c23b9b6ab0b8faed9Exploitation
| CVE ID | Celebrity Vulnerability | Affected Product | CWE ID | Associated Actors / Attacks |
|---|---|---|---|---|
CVE-2026-16812 |
Zero-Day, CISA KEV | Arista VeloCloud Orchestrator (VCO) On-Prem (5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, 7.0.x before 7.0.0.1) |
CWE-78 |
— |
CVE-2026-12569 |
Zero-Day, CISA KEV | PTC Windchill PDMLink and FlexPLM — all CPS (Critical Patch Set) versions, including releases prior to 11.0 M030 |
CWE-502, CWE-20 |
Cl0p |
CVE-2026-16723 |
Zero-Day, CISA KEV | Alibaba FastJson 1.x (1.2.68 through 1.2.83) |
CWE-502, CWE-20 |
— |
CVE-2026-42897 |
Zero-Day, CISA KEV | Microsoft Exchange Server | CWE-79 |
TA488, OWAReaper |
CVE-2026-20316 |
Zero-Day, CISA KEV | Cisco Secure Firewall Management Center (FMC) Software (7.0.x through 7.7.x and 10.0.x releases prior to the fixed hot-fix builds) |
CWE-259 |
— |
All five CVEs this week are tracked as Zero-Day, Celebrity Vulnerabilities and listed in the CISA KEV catalog.
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*CWE-78T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter, T1068 Exploitation for Privilege EscalationCVE-2026-16812 is a maximum-severity, unauthenticated OS command injection flaw in the on-premises Arista VCO, used to centrally manage VeloCloud SD-WAN deployments and edge devices. It lets a remote attacker reach privileged internal functionality never intended for external exposure, without any credentials.
cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*, cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*CWE-502, CWE-20T1190 Exploit Public-Facing Application, T1059 Command and Scripting InterpreterCl0p-affiliated operators target internet-exposed PTC Windchill and FlexPLM deployments, chaining a pre-auth FlexPLM WSDL disclosure with this Windchill login servlet flaw (CVE-2026-12569) for unauthenticated RCE across all CPS (Critical Patch Set) versions prior to 11.0 M030.
CVE-2026-16723 (Alibaba FastJson 1.x 1.2.68–1.2.83, CWE-502/CWE-20) is an unauthenticated RCE in FastJson's default deserialization settings, already exploited in the wild. CVE-2026-42897 (Microsoft Exchange Server, CWE-79) is the Outlook Web Access XSS flaw TA488 weaponized to deploy the OWAReaper backdoor — patch here. CVE-2026-20316 (Cisco Secure Firewall Management Center, CWE-259) is a static, built-in low-privilege credential affecting 7.0.x–7.7.x and 10.0.x builds prior to the fixed hot-fix — patch here. All three carry T1190 Exploit Public-Facing Application in their TTP chain.
Threat Actors
TA488, also tracked as Void Blizzard or Laundry Bear, is a Russia-origin threat actor motivated by information theft and espionage, most recently weaponizing CVE-2026-42897 to deploy the OWAReaper backdoor.
CVE-2026-42897TTPs: Spans Resource Development, Initial Access, Execution, Defense Evasion, Persistence, Credential Access, Collection, Command and Control, and Exfiltration — notably T1566 Phishing, T1203 Exploitation for Client Execution, T1555 Credentials from Password Stores, and T1041 Exfiltration Over C2 Channel. Full TTP mapping (30 techniques) is available via Uni5Xposure.
Guidance
Security teams should prioritize the five exploited vulnerabilities and block indicators tied to TA488 and OWAReaper, Tengu.
HivePro Uni5 customers get comprehensive threat exposure insights and can act on them effortlessly via the Uni5 dashboard.
01Run a Scan
Discover assets impacted by the five exploited vulnerabilities: CVE-2026-16812, CVE-2026-12569, CVE-2026-16723, CVE-2026-42897, and CVE-2026-20316.
02Test Security Controls
Test security control efficacy by simulating the attacks related to threat actor TA488 and malware OWAReaper, Tengu in Breach and Attack Simulation (BAS).
Publications This Week
CVE-2026-20316: Cisco Secure FMC Skeleton Key Exploited as a Zero-DayDefinitions & Indicators
Known Exploited Vulnerabilities (KEV): Vulnerabilities with public exploits or PoC code available, posing a high risk of harm to an organization's systems or data if unaddressed.
Celebrity Vulnerabilities: Vulnerabilities branded with catchy names and logos due to their profound, multifaceted impact, giving threat actors opportunities to breach sensitive systems and compromise critical information.
| Attack Name | Type | Value |
|---|---|---|
| OWAReaper | SHA256 | 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4 |
| OWAReaper | Domains | asecdns[.]com, acocdn[.]com, dnsrecursive[.]eu, tdndns[.]com |
| Tengu | SHA256 | 897226af37990fa60f25fea00b0509faa0e78d8bee10875c23b9b6ab0b8faed9 |
A comprehensive list of IOCs (Indicators of Compromise) associated with the executed attacks is available on the Uni5Xposure platform.
Next Steps
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.