CVE-2026-0456Active Exploitation

MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

5.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 2 signals
  • Peaked 3d ago at 3 mentions (2026-03-13); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-03-12: 1Mentions · 2026-03-13: 3Mentions · 2026-03-14: 2Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-23: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-13: 3Active Exploitation · 2026-03-14: 203-1203-1303-1403-2003-23
Signal classification2 categories
Active Exploitation
675.0%
PoC
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-121
Active Exploitation1
2026-03-133
Active Exploitation3
2026-03-142
Active Exploitation2
2026-03-201
PoC1
2026-03-231
PoC1
Full discourse8 posts
  • ThreatCluster@threatcluster
    Active Exploitation

    Over 200 US healthcare orgs hit by March 2026 ransomware campaign exploiting unpatched MedTech CVE-2026-0456, disrupting EHRs and patient care. FBI links activity to known group. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-healthcare-sector-in-2026-9f00b134

    Post summary

    A March 2026 ransomware campaign exploited the unpatched MedTech CVE‑2026‑0456, impacting more than 200 U.S. healthcare organizations and disrupting EHRs, with the FBI linking the activity to a known threat group.

    0001090
    101 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    DarkLock ransomware hits 500+ critical infrastructure orgs, exploiting zero-day CVE-2026-0456. Energy and healthcare report major service disruptions. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-critical-infrastructure-in-a933b8ab

    Post summary

    DarkLock ransomware is actively exploiting the zero‑day CVE‑2026‑0456 against more than 500 critical infrastructure organizations, causing significant disruptions in energy and healthcare sectors.

    00010109
    100 followersView on X
  • warp_polaris@warp_polaris
    PoC

    CVE-2026-0456 <iframe src="https://github.com/user-attachments/assets/a22f0635-4b4f-49a6-860e-465ea726fe58"></iframe><object data="https://github.com/user-attachments/assets/a22f0635-4b4f-49a6-860e-465ea726fe58" type="image/svg+xml"></object><svg onload="alert(document.cookie)" xmlns="http://w3.org/2000/svg"></svg><svg xmlns="http://w3.org/2000/svg"><script>alert('PT')</script></svg>

    Post summary

    The post shares a PoC link and basic XSS script snippets for CVE-2026-0456, but offers no exploitation tool, patch, or detailed technical info.

    0000020
  • warp_polaris@warp_polaris
    PoC

    CVE-2026-0456 <iframe src="https://github.com/user-attachments/assets/a22f0635-4b4f-49a6-860e-465ea726fe58"></iframe><object data="https://github.com/user-attachments/assets/a22f0635-4b4f-49a6-860e-465ea726fe58" type="image/svg+xml"></object><svg onload="alert(document.cookie)" xmlns="http://www.w3.org/2000/svg"></svg><svg xmlns="http://www.w3.org/2000/svg"><script>alert('PT')</script></svg>

    Post summary

    The post links to a GitHub asset that likely contains a PoC for CVE‑2026‑0456, but it lacks explicit exploitation details, references to active attacks, or patch information.

    0000033
  • ThreatCluster@threatcluster
    Active Exploitation

    Massive ransomware attack hits multiple US healthcare orgs, with over 1M patient records accessed or encrypted via new RansomX variant exploiting CVE-2026-0456. FBI is investigating. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-healthcare-sector-in-2026-15a6d263

    Post summary

    A large ransomware campaign targeting U.S. healthcare organizations is actively exploiting CVE-2026-0456, with FBI investigation underway.

    0000057
    101 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Over 50 financial institutions hit by global ransomware campaign exploiting zero-day CVE-2026-0456 in banking software, FBI issues emergency advisory as data breaches impact millions. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-global-financial-instituti-3edf2df0

    Post summary

    CVE‑2026‑0456 is being actively exploited in a ransomware campaign that has impacted more than fifty financial institutions, prompting an emergency advisory from the FBI.

    00000100
    101 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Massive ransomware attack hits US healthcare sector, exploiting MedSys CVE-2026-0456 and compromising 1.5M patient records as DarkSky demands $10M ransom, disrupting hospital operations. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-healthcare-sector-in-2026-aaae1f0c

    Post summary

    The post reports that CVE-2026-0456 was exploited in a large ransomware campaign against U.S. healthcare providers, compromising 1.5 million patient records.

    0000062
    100 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    DarkSky ransomware hits over 500 orgs in March 2026, exploiting zero-day CVE-2026-0456 to disrupt energy and transport operations, with $10M+ in demands. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-targets-critical-infrastructure-in-b59601ef

    Post summary

    DarkSky ransomware is actively exploiting CVE-2026-0456 against critical infrastructure, affecting more than 500 organizations and demanding over $10M in ransoms.

    0000094
    100 followersView on X

Explore more