Vulnerabilities · 80 days ago

Public Exploits Now Feed a Custom Cobalt Strike Loader

The break is no longer a single product flaw. StrikeShark now looks like a broad access campaign that reuses public web-app exploits to get in, then hands the foothold to SharkLoader so Cobalt Strike can stay on the network and move beyond the first compromised host.

Kaspersky ties the activity to a custom loader that deploys Cobalt Strike Beacon and to opportunistic abuse of many internet-facing vulnerabilities across Microsoft Exchange, Openfire, GeoServer, Fortinet FortiOS, F5 BIG-IP, Cisco IOS XE, Zimbra, Apache Shiro, and Hikvision. The set includes older flaws such as CVE-2021-26855, CVE-2023-32315, and CVE-2024-36401, and the campaign uses publicly available proof-of-concept exploits rather than bespoke zero-days.

The practical change is the blast radius. Any exposed admin or app service can become the same intrusion path, so patching one named CVE does not remove the campaign pattern once a reachable service is left open.

CVE-2023-32315

NVD KEV

Known exploited · CISA KEV

CVSS 8.6 HIGH: openfire is an XMPP server licensed under the Open Source Apache License. EPSS 100% (100th percentile).

CISA federal remediation date Sep 14 · date passed

CVE-2021-26855

NVD KEV

Known exploited · CISA KEV

CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date May 3 · date passed

CVE-2024-36401

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: geoServer is an open source server that allows users to share and edit geospatial data. EPSS 100% (100th percentile).

CISA federal remediation date Aug 5 · date passed

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: Microsoft

Vendor digest: Cisco

Vendor digest: Fortinet

Vendor digest: F5

Part of the PlainSec briefing for 2026-06-27

Editions

Related stories