
CVE-2023-3519, CVE-2025-5777, CVE-2023-48788, CVE-2024-57727: Multi-Vendor RCE Enables Ransomware Surge (June 2026)
CVE-2023-3519, CVE-2025-5777, CVE-2023-48788, CVE-2024-57727 — Multi-Vendor Remote Code Execution
INC ransomware is leveraging four critical vulnerabilities (CVE-2023-3519, CVE-2025-5777, CVE-2023-48788, CVE-2024-57727) to gain initial access and execute code on enterprise networks. All are rated critical and are actively exploited in the wild, with no reliable workarounds. These CVEs enable remote code execution (RCE) and privilege escalation, facilitating ransomware deployment and lateral movement. INC ransomware has used these flaws in over 830 confirmed attacks since August 2023, targeting legal, manufacturing, construction, technology, and healthcare sectors.
Attack Vector
Attackers exploit unpatched systems exposed to the internet, chaining these CVEs to bypass authentication, dump credentials (notably from Veeam backup servers), and deploy Rust-based encryptors. The attack chain includes use of LOLBins and commercial remote monitoring and management (RMM) tools for lateral movement and data exfiltration. Once inside, adversaries escalate privileges and disable security controls before detonating ransomware payloads. The campaign is highly automated, and evidence of exploitation can be found in authentication logs, backup server access, and anomalous RMM tool usage.
Who Is at Risk
Organizations running unpatched versions of affected products (details per CVE) are at immediate risk. The primary targets are US-based legal, manufacturing, construction, technology, and healthcare firms, but collateral exposure is possible across vendor and partner networks. Over 120 incidents were recorded in Q1 2026 alone, making this a top-tier threat for any enterprise with internet-facing infrastructure.
Patch & Mitigate
- Patch: Apply vendor-released security updates for CVE-2023-3519, CVE-2025-5777, CVE-2023-48788, and CVE-2024-57727 immediately. Prioritize internet-facing and backup infrastructure.
- Workaround: None reliably available. Isolate vulnerable systems if patching is delayed.
- Detect: Monitor for unusual authentication attempts, credential access on backup servers, unauthorized RMM tool activity, and execution of unsigned binaries (LOLBins).
MITRE ATT&CK
- T1078 — Valid Accounts: Attackers use stolen credentials from backup servers for lateral movement.
- T1219 — Remote Access Software: Commercial RMM tools are abused for persistence and control.
- T1486 — Data Encrypted for Impact: Rust-based ransomware encryptors deployed to disrupt operations.
Source: https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

