Back to Blog
CVE-2021-26855 et al.: Multi-Vendor RCE Flaws Enable Cobalt Strike Deployment (June 2026)
vulnerabilities

CVE-2021-26855 et al.: Multi-Vendor RCE Flaws Enable Cobalt Strike Deployment (June 2026)

breachwire TeamJun 27, 20262 min read

CVE-2021-26855 et al. — Multi-Vendor Remote Code Execution

A coordinated exploitation campaign is actively leveraging CVE-2021-26855, CVE-2023-32315, CVE-2024-36401, and nine other high-severity vulnerabilities (CVSS 8.0–10.0) to gain initial access and deploy Cobalt Strike Beacon via the SharkLoader malware. These CVEs affect a range of enterprise software and are confirmed as actively exploited in the wild.

Attack Vector

Attackers use automated scanning to identify unpatched systems vulnerable to remote code execution and authentication bypass. Initial access is achieved through exploitation of exposed services (e.g., Microsoft Exchange, Fortinet, F5, Ivanti, QNAP, Hikvision, Apache Shiro). SharkLoader is delivered via DLL hijacking and custom droppers, which then deploy Cobalt Strike for persistence and lateral movement. Post-compromise activity includes credential theft and reconnaissance, with no confirmed data exfiltration at this stage.

Who Is at Risk

Targets include government and software development organizations in Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. Any organization running unpatched versions of affected products—especially Microsoft Exchange, Fortinet FortiOS, F5 BIG-IP, Ivanti Connect Secure, QNAP NAS, Hikvision cameras, and Apache Shiro—is at immediate risk.

Patch & Mitigate

  • Patch: Apply vendor security updates for all listed CVEs immediately. Prioritize Microsoft Exchange (CVE-2021-26855), Fortinet (CVE-2022-40684, CVE-2024-21762), F5 (CVE-2023-46747), and Ivanti (CVE-2023-20198) patches. Deadline: as soon as possible.
  • Workaround: Disable or restrict access to management interfaces and remote administration ports where patching is delayed.
  • Detect: Monitor for anomalous DLL loads, suspicious child processes (e.g., rundll32.exe spawning Cobalt Strike), and outbound connections to unknown C2 infrastructure. Review logs for exploitation attempts matching the listed CVEs.

MITRE ATT&CK

  • T1190 — Exploit Public-Facing Application: Attackers exploit internet-facing services using known CVEs for initial access.
  • T1055 — Process Injection: SharkLoader and Cobalt Strike use DLL hijacking and process injection for persistence and evasion.
  • T1087 — Account Discovery: Post-compromise, attackers enumerate accounts and credentials for lateral movement.

Source: https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: