
CVE-2026-39987, CVE-2026-41176: NadMesh Botnet — Cloud Credential Theft via AI Services (July 2026)
CVE-2026-39987, CVE-2026-41176 — NadMesh Botnet Targeting AI Services
CVE-2026-39987 and CVE-2026-41176 (high severity) are actively exploited by the NadMesh botnet to compromise cloud infrastructure by stealing AWS keys and Kubernetes tokens from exposed AI services. The vulnerabilities allow remote code execution and credential harvesting, with no authentication required in many cases.
Attack Vector
NadMesh scans for publicly accessible Docker APIs, Jenkins consoles, unauthenticated Redis services, and hosts with weak Telnet/SSH credentials. Once access is gained, the botnet extracts sensitive cloud credentials from environment variables and configuration files. Indicators of compromise include outbound connections to 209.99.186.235 and cdnorigin.net, and the presence of SHA1:31c69b3e12936abca770d430066f379ec1d997ec in infected systems. NadMesh uses persistence and obfuscation to evade removal, and leverages multiple exploits including Docker API RCE and Jenkins script RCE.
Who Is at Risk
Organizations running AI services, Docker, Jenkins, or Redis instances exposed to the internet without proper authentication are at immediate risk. Cloud environments with weak SSH/Telnet passwords or default credentials are especially vulnerable. The campaign is global in scope and targets any accessible infrastructure, regardless of industry.
Patch & Mitigate
- Patch: Apply all available security updates for Docker, Jenkins, and Redis immediately. CVE-2026-39987 and CVE-2026-41176 patches should be prioritized; also address CVE-2022-22947 and CVE-2017-12611 if present.
- Workaround: Restrict public access to management interfaces, enforce strong authentication, and disable unused services.
- Detect: Monitor for connections to 209.99.186.235 and cdnorigin.net, and scan for the listed SHA1 hash. Review logs for unauthorized API calls or suspicious credential access.
MITRE ATT&CK
- TA0001 — Initial Access: NadMesh exploits exposed services and weak credentials to gain entry.
- TA0006 — Credential Access: The botnet extracts cloud and Kubernetes credentials from compromised systems.
- TA0040 — Impact: Attackers achieve persistent unauthorized access and control over cloud infrastructure.
Source: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

