Exploit
#threatreport #HighCompleteness
Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries | 20-07-2026
Source: https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve
Key details below ↓
💀Threats:
Adaptixc2_tool, Supershell, Nginx_rift_vuln, Clickfix_technique, Impacket_tool, Goby_tool,
🎯Victims: Government, Universities, Healthcare, Financial services, Academic, Private sector
🏭Industry: Government, Financial, Education, Healthcare
🌐Geo: Italy, Brazil, France, Vietnam, Singapore, Australia, Chinese, South korea, United states, Indonesia, United kingdom, Ireland, New zealand
🔓CVEs: CVE-2023-27350 \[[Vulners](https://vulners.com/cve/CVE-2023-27350)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- papercut papercut_mf (<20.1.7, <21.2.11, <22.0.9)
- papercut papercut_ng (<20.1.7, <21.2.11, <22.0.9)
CVE-2026-4480 \[[Vulners](https://vulners.com/cve/CVE-2026-4480)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: Unknown
Soft:
- redhat openshift_container_platform (4.0)
- samba (<4.2.1)
- redhat enterprise_linux (7.0, 8.0, 9.0, 10.0)
CVE-2026-26980 \[[Vulners](https://vulners.com/cve/CVE-2026-26980)]
- CVSS V3.1: *9.4*,
- Vulners: Exploitation: True
Soft:
- ghost (<6.19.1)
CVE-2024-3273 \[[Vulners](https://vulners.com/cve/CVE-2024-3273)]
- CVSS V3.1: *7.3*,
- Vulners: Exploitation: True
Soft:
- dlink dns-320l_firmware (1.01.0702.2013, 1.03.0904.2013, 1.11)
CVE-2026-20253 \[[Vulners](https://vulners.com/cve/CVE-2026-20253)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- splunk (<10.0.7, <10.2.4)
CVE-2026-42945 \[[Vulners](https://vulners.com/cve/CVE-2026-42945)]
- CVSS V3.1: *8.1*,
- Vulners: Exploitation: True
Soft:
- f5 dos (le4.7.0, 4.8.0)
- f5 nginx_gateway_fabric (le1.6.2, le2.5.1)
- f5 nginx_ingress_controller (le3.7.2, le4.0.1, le5.4.1)
- f5 nginx_instance_manager (le2.21.1)
...
CVE-2017-10271 \[[Vulners](https://vulners.com/cve/CVE-2017-10271)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- oracle weblogic_server (10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0)
📚TTPs:
⚔️Tactics: 2
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1190, T1583.001, T1583.003, T1588.002, T1588.005, T1595.002
🧨IOCs:
- IP: 2
- File: 4
- Hash: 1
- Domain: 4
💽Software: NGINX, PaperCut, WebLogic, mysql, GoDaddy
🔢Algorithms: sha256
🔠Functions: system
⚙️Win Services: print-spooler
📜Programming Languages: golang, javascript, python
#threatreport:
In mid-2026, significant vulnerabilities were discovered in NGINX and Ghost CMS, leading to potential cyber exploits targeting governmental and financial institutions across eleven countries. The two primary vulnerabilities included NGINX Rift (CVE-2026-42945), a heap overflow in the NGINX rewrite module, and a blind SQL injection in the Ghost CMS Content API (CVE-2026-26980). Public exploit code for both was released shortly after their discovery, prompting attackers to develop and deploy creative methods to leverage these vulnerabilities.
An exposed directory on an active Singapore-based VPS revealed the operational details of a cyber threat actor leveraging these vulnerabilities. The directory, housing a variety of exploits, contained tools for multiple attack techniques, including reverse shell setup and out-of-band (OOB) DNS callbacks to confirm malware execution. The target sectors indicated a strategic approach, primarily focusing on high-value entities like federal governments, educational institutions, healthcare providers, and financial services.
The NGINX Rift vulnerability was used in targeted attempts to exploit live infrastructure. An exploitation script (http://poc.py) relied on specific memory addresses and settings that necessitated a low-security environment, indicating a phase of development rather than direct application on active targets. The actor’s exploration revealed little success during these attempts.
On the other hand, the Ghost CMS exploit allowed the attacker to interact with the database without authentication, making it easier to extract sensitive information. By running a public exploit script, the actor conducted checks to identify vulnerable hosts and subsequently attempted data extraction. The implications of CVE-2026-26980 extend beyond this singular event, as it had been previously associated with larger campaigns aimed at mass exploitation.
Additional exploits in the toolkit included those targeting well-known vulnerabilities in systems such as PaperCut, Oracle WebLogic, and D-Link NAS devices. The operator's use of OOB verification methods, like directing DNS queries to uniquely generated subdomains, offered a means to validate successful exploit execution despite potential network response filtering.
Command and control infrastructure included the presence of widely recognized exploitation frameworks like AdaptixC2 and Supershell, although these tools were not directly linked to any specific intrusion captured in the analysis. The operational artifacts uncovered indicated a systematic approach to database exploitation, along with diligent targeting across nations including Brazil, France, South Korea, and others, primarily within sectors that handle sensitive data.
While specific compromise outcomes were not confirmed in the gathered evidence, this activity exemplified a competent cyber threat actor exploiting newly discovered vulnerabilities and old, effective techniques with awareness and precision. The existence of these exploits and their deliberate targeting underscores the need for heightened vigilance and proactive defense measures within the cybersecurity landscape to mitigate similar attacks.
Post summary
The report documents the release of public exploit code for NGINX Rift (CVE-2026-42945) and Ghost CMS blind SQL injection (CVE-2026-26980), including detailed technical info and evidence of active exploitation attempts across multiple high-value sectors, underscoring an increased threat landscape.