CVE-2024-4358Active Exploitation(telerik / report_server_2024)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for telerik report_server_2024 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-07-04. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • report_server_2024

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
report_server_2024

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-04: 1Active Exploitation · 2026-03-04: 1Technical Details · 2026-03-04: 103-04
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 FulcrumSec Claims LexisNexis AWS Breach: 2.04GB Stolen After React2Shell Exploit FulcrumSec alleges it exploited an unpatched React2Shell RCE (CVE-2024-4358) to compromise an AWS ECS task role with broad read permissions and then access Redshift, multiple VPC databases, and AWS Secrets Manager—claiming ~3.9M records, cloud user profiles (including .gov accounts), enterprise customer data, and plaintext secrets/credentials. The incident highlights cloud IAM over-privilege + weak credential hygiene (e.g., “Lexis1234”) as a fast path from a web-app bug to full cloud data warehouse exposure. 🎯 Target: Global/Legal Data & Government-Adjacent Users #️⃣ Category: #DataBreach #CyberCrime #Vulnerability #TargetedAttacks 🔗 URL: https://cyberpress.org/lexisnexis-data-breach/

    Post summary

    FulcrumSec claims that the unpatched CVE‑2024‑4358 React2Shell RCE was exploited to breach LexisNexis AWS, resulting in a significant data breach and the theft of millions of records, yet no PoC, exploit code, or patch details are provided.

    0000176
    261 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptelerikreport_server_2024---

Explore more