Vulnerabilities · 88 days ago

Exposed Staging Server Shows Perimeter Breaches Spreading Inward

The real break is not the edge appliance itself. Once attackers get in through a perimeter device, they can turn that foothold into hidden access to identity systems, SAP, Oracle, and internal data streams that patching the original box does not erase.

CloudSEK mapped Operation Escaneo from an exposed staging server and tied it to active exploitation of Fortinet FortiOS and Ivanti Connect Secure flaws, with confirmed beacons from at least five victims across Mexican government, finance, telecom, transport, and utilities. The exposed artifacts showed tunnels over HTTP, a router-based GRE path, SAP command use, Active Directory maps, private keys, and service-account secrets pulled from victim networks.

That makes the campaign more than a perimeter-bug run. It shows how one appliance compromise can become a durable internal route that slips past host-based monitoring and exposes downstream systems long after the initial device is cleaned up.

CVE-2024-21887

NVD KEV

Known exploited · CISA KEV

CVSS 9.1 CRITICAL: a command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jan 22 · date passed

CVE-2023-46805

NVD KEV

Known exploited · CISA KEV

CVSS 8.2 HIGH: an authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jan 22 · date passed

CVE-2025-0282

NVD KEV

Known exploited · CISA KEV

CVSS 9 CRITICAL: a stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jan 15 · date passed

CVE-2022-42475

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8… Known ransomware campaign use. EPSS 99% (100th percentile).

CISA federal remediation date Jan 3 · date passed

CVE-2024-21762

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13… Known ransomware campaign use. EPSS 84% (100th percentile).

CISA federal remediation date Feb 16 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Fortinet

Vendor digest: Ivanti

Part of the PlainSec briefing for 2026-06-19

Editions

Related stories