CVE-2025-6789Active Exploitation

MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 2 signals
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Active Exploitation · 2026-03-12: 2Active Exploitation · 2026-03-13: 2Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 103-1203-13
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • ThreatCluster@threatcluster
    Active Exploitation

    Massive March 2026 ransomware campaign hits 500+ critical infrastructure orgs, exploiting CVE-2025-6789 in widely used software, demanding over $10M in ransoms. Emergency patches issued. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-critical-infrastructure-in-965c003f

    Post summary

    A widespread ransomware campaign exploited CVE‑2025‑6789 across more than 500 critical infrastructure organizations in March 2026, demanding large ransoms and prompting emergency patches.

    00100228
    100 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Global ransomware campaign hits 200+ financial institutions in March 2026, exploiting CVE-2025-6789 to deploy CryptoLock 2.0 and exfiltrate data from at least 50 banks. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-hits-global-financial-institutions-ca4ebc52

    Post summary

    The post reports an ongoing ransomware campaign that is actively exploiting CVE‑2025‑6789 against numerous financial institutions.

    00010147
    100 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Massive ransomware attack in March 2026 disrupts energy and healthcare infrastructure, exploiting CVE-2025-6789. Over 200 orgs impacted as FBI warns of follow-on activity. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-critical-infrastructure-in-266dc702

    Post summary

    The text reports a large‑scale ransomware campaign that exploited CVE‑2025‑6789, with the FBI warning of continued activity targeting critical infrastructure.

    00000156
    100 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Major cyber heist hits multiple financial institutions, exploiting CVE-2025-6789 since Mar 5, 2026, with over 1M customer records and financial data stolen. Emergency patching underway. #DataBreach https://threatcluster.io/cluster/orange-highlights-cyber-attack-as-a-robbery-not-a-malfunctio-13840487

    Post summary

    CVE‑2025‑6789 has been actively exploited in a large cyber heist targeting financial institutions, with emergency patching underway to address the breach.

    00000131
    100 followersView on X

Explore more