Digital shields failing against critical RCE, zero-day, and takeover vulnerabilities.

Daily Cybersecurity News - February 27, 2026

Trend Micro Patches Critical RCE Flaws

Critical

Executive Summary

Trend Micro has released patches for two critical remote code execution vulnerabilities, CVE-2025-71210 and CVE-2025-71211, affecting its Apex One endpoint security solution. The flaws have been addressed, and customers are strongly encouraged to apply the updates as soon as possible.

Vulnerability Details

  • Affected Product: Trend Micro Apex One 2019 (On-premise).
  • Identifier: CVE-2025-71210, CVE-2025-71211.
  • CVSS Score: 9.8 (Critical).
  • Exploitation Status: No in-the-wild exploitation has been reported.

Risk & Impact

  • Triage: Immediate patching is recommended due to the critical severity and potential for full system takeover.
  • Attack Vector: An unauthenticated, remote attacker can exploit a path traversal weakness in the Apex One management console to upload malicious files and execute arbitrary code. Successful exploitation requires network access to the management console.
  • Ease of Exploit: Exploitation requires specific conditions to be met, but the vendor urges customers not to delay patching.

Action Plan

  • Immediate Action: On-premise customers should upgrade to Critical Patch Build 14136. SaaS versions of Apex One have been automatically updated.
  • Workaround: If patching is not immediately possible, restrict access to the management console by applying source IP address restrictions, especially for consoles exposed to the internet.
  • Detection: Monitor for any unauthorized file uploads or command execution on systems running the Apex One management console.

Relevant professional terms

Remote Code Execution (RCE)
An attack in which a threat actor can remotely execute commands of their choosing on a target machine, regardless of geographic location.
Path Traversal
A type of security vulnerability that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference file paths.

Juniper Routers Face Critical Takeover Flaw

Critical

Executive Summary

A critical vulnerability, identified as CVE-2026-21902, in Juniper Networks' Junos OS Evolved allows an unauthenticated, network-based attacker to execute remote code with root privileges, leading to a full takeover of affected PTX Series routers. Juniper has released patches to address this flaw, which has a patched status.

Vulnerability Details

  • Affected Product: Junos OS Evolved on PTX Series routers, versions before 25.4R1-S1-EVO and 25.4R2-EVO.
  • Identifier: CVE-2026-21902.
  • CVSS Score: 9.8 (Critical).
  • Exploitation Status: No known malicious exploitation at the time of the advisory's publication.

Risk & Impact

  • Triage: Urgent; immediate patching or mitigation is required due to the critical severity and potential for full system compromise.
  • Attack Vector: An unauthenticated attacker with network access can exploit an incorrect permission assignment in the 'On-Box Anomaly Detection' framework, which is accessible via an externally exposed port.
  • Ease of Exploit: The vulnerability is considered simple to exploit as the vulnerable service is enabled by default and requires no authentication.

Action Plan

  • Immediate Action: Upgrade to Junos OS Evolved versions 25.4R1-S1-EVO, 25.4R2-EVO, or 26.2R1-EVO and later.
  • Workaround: If patching is not immediately possible, restrict access to the vulnerable endpoints to trusted networks using firewall filters or Access Control Lists (ACLs). Alternatively, disable the service with the command: `request pfe anomalies disable`.
  • Detection: Monitor network logs for unusual activity or connection attempts to the exposed service port on PTX Series routers.

Relevant professional terms

Root Privileges
The highest level of permission in a Unix-like operating system, allowing a user to access all files and commands and have complete control over the system.
Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to execute arbitrary commands or code on a target machine or in a target process from a remote location.

Cisco Zero-Day Enables Total Takeover

Critical

Executive Summary

A critical authentication bypass vulnerability, identified as CVE-2026-20127, has been discovered in Cisco Catalyst SD-WAN solutions. This zero-day flaw is under active exploitation, allowing unauthenticated remote attackers to gain administrative privileges and compromise the network fabric.

Vulnerability Details

  • Affected Product: Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage) in On-Prem, Cisco Hosted, and FedRAMP deployments. Affected versions include releases prior to 20.9, and various builds within the 20.9.x, 20.12.x, 20.15.x, and 20.18.x series.
  • Identifier: CVE-2026-20127
  • CVSS Score: 10.0 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching is required. This vulnerability allows for complete compromise of the SD-WAN fabric.
  • Attack Vector: An unauthenticated, remote attacker can exploit this flaw by sending a crafted request to the device. This is due to a flaw in the peering authentication mechanism, allowing the attacker to add a rogue, actor-controlled peer to the network management plane.
  • Ease of Exploit: The attack complexity is considered low, requiring no special privileges or user interaction.

Action Plan

  • Immediate Action: Upgrade to a patched software version immediately. Fixed releases include 20.9.8.2, 20.12.6.1, 20.15.4.2, and 20.18.2.1, among others.
  • Workaround: Cisco has stated there are no workarounds that address this vulnerability.
  • Detection: Hunt for indicators of compromise (IOCs), such as unexpected log entries in /var/log/auth.log. Threat actors have been observed downgrading software to exploit older bugs for privilege escalation (like CVE-2022-20775), creating mimicked local user accounts, and adding SSH authorized keys for root access.

Relevant professional terms

Zero-Day Vulnerability
A security flaw in software or hardware that is unknown to the party or parties responsible for patching or otherwise fixing the flaw. The term "zero-day" refers to the fact that the vendor has zero days to fix the issue before it is potentially exploited by attackers.
Threat Actor
An individual or group that performs malicious activities (cyberattacks) against an organization or individual. Threat actors can be categorized by their motivations, such as nation-states, cybercriminals, hacktivists, or insiders.
Source: Dark Reading

North Korean Actors Exploit Hiring Process

Executive Summary

North Korean threat actors are posing as recruiters to target software developers with fake job opportunities. This social engineering campaign entices candidates with coding challenges that are actually trojanized applications, leading to malware installation upon execution.

Key TTPs

  • Initial Access: Phishing via fake job offers on platforms like LinkedIn.
  • Execution: Victims are persuaded to download and run malicious code from repositories like GitHub, disguised as a skills test.

Campaign Analysis

This campaign demonstrates a tactical evolution, exploiting the developer hiring workflow to establish persistent access for espionage or financial theft. The use of trojanized developer tools and fake coding assignments increases the likelihood of successful execution.

Targeting & Infrastructure

  • Target Profile: Software developers and engineers, particularly those in the AI, cryptocurrency, and financial services sectors.
  • Infrastructure: Malicious packages hosted on public repositories like npm and PyPI, and command-and-control (C2) servers.

Relevant Terms

  • Phishing: A cyberattack where threat actors, disguised as a trusted entity, trick a victim into opening a malicious email, message, or link.
  • Social Engineering: The psychological manipulation of people into performing actions or divulging confidential information.

FreePBX Flaw Enables Mass Infection

Executive Summary

Attackers are exploiting a command injection vulnerability to install web shells on Sangoma FreePBX instances, leading to the compromise of approximately 900 systems. The campaign, attributed to the INJ3CTOR3 hacking group, leverages the EncystPHP web shell for remote access and control.

Key TTPs

  • Initial Access: Exploitation of a post-authentication command injection vulnerability (CVE-2025-64328) in the FreePBX endpoint manager's administrative interface.
  • Execution: The vulnerability allows for arbitrary shell command execution, which is used to deploy the EncystPHP web shell.
  • Persistence: The malware creates a new root-level user and injects an SSH public key to maintain persistent control over the compromised host.

Campaign Analysis

This campaign highlights the significant impact of exploiting known vulnerabilities in widely used open-source management tools. The attackers' use of a sophisticated web shell demonstrates a clear intent to establish long-term access for further malicious activities.

Targeting & Infrastructure

  • Target Profile: Organizations using Sangoma FreePBX, a popular open-source IP telephone system management tool.
  • Infrastructure: Approximately 900 FreePBX instances have been identified as compromised and are currently running web shells.

Actionable Intelligence

  • IPs: 45.234.176[.]202
  • Domains: crm.razatelefonia[.]pro

Relevant Terms

  • Web Shell: A malicious script uploaded to a server that allows an attacker to execute commands and maintain remote access.
  • Command Injection: A type of cyberattack that involves executing arbitrary commands on a host operating system by exploiting a vulnerable application.
Source: SecurityWeek

Aeternum Botnet Hardens C2 on Blockchain

Executive Summary

The Aeternum botnet loader utilizes the Polygon blockchain for its command-and-control (C2) infrastructure, making it highly resilient to traditional takedown efforts. This malware-as-a-service is sold on underground forums, allowing threat actors to deploy payloads via immutable smart contracts.

Key TTPs

  • Execution: Infected hosts query public Polygon RPC endpoints to read encrypted commands from a smart contract, which are then decrypted and executed locally.
  • Defense Evasion: The malware employs anti-virtual machine checks, geofencing to avoid Russian systems, and uses API hashing to hide its functions.

Campaign Analysis

Aeternum represents a significant evolution in malware design by removing the central servers that law enforcement typically targets. This model lowers operational costs and complicates disruption, as the C2 channel is permanent and globally accessible on the blockchain.

Targeting & Infrastructure

  • Target Profile: The malware is sold as a service, allowing various threat actors to target any industry.
  • Infrastructure: C2 is operated via smart contracts on the public Polygon blockchain, with no central servers, domains, or hosting providers required.

Relevant Terms

  • Command and Control (C2): The server infrastructure that attackers use to send commands to and receive data from compromised devices in a botnet.
  • Smart Contract: A program stored on a blockchain that automatically executes when predetermined conditions are met, used by Aeternum to issue commands.
Source: SecurityWeek

Intellexa Chiefs Jailed For Spyware Scandal

Executive Summary

A Greek court sentenced four executives from spyware firm Intellexa for their role in the "Greek Watergate" scandal, which involved the illegal wiretapping of politicians, journalists, and officials using the Predator spyware. This landmark case marks one of the first criminal convictions of commercial spyware operators in Europe.

The Scheme

  • TTP 1: Deployed Predator spyware to infiltrate mobile phones, enabling full access to microphones, cameras, and personal data.
  • TTP 2: Used one-time malicious links sent via SMS and encrypted messaging apps to trick targets into installing the spyware.
  • TTP 3: Leveraged zero-day vulnerabilities in mobile browsers like Chrome and Safari to gain initial access to devices.

The Players

  • Threat Actor: Intellexa
  • Facilitators Arrested: Tal Dilian, Sara Hamou, Felix Bitzios, and Yiannis Lavranos

The Consequence

  • Outcome: The executives were found guilty of breaching telephone confidentiality and illegally accessing information systems, receiving sentences of up to eight years, which were suspended pending appeal.

Strategic Takeaway

This verdict sets a critical legal precedent by holding commercial spyware vendors criminally accountable for the misuse of their surveillance technology, signaling a shift from fines to personal liability.

Relevant Terms

  • Spyware: Malicious software designed to secretly enter a device, gather sensitive information, and relay it to an external party.
  • Zero-Day Vulnerability: A flaw in software or hardware that is unknown to the vendor and for which no patch exists, making it a high-value target for attackers.
Source: TechCrunch