CVE-2026-25212Disclosure(percona / monitoring_and_management)

HIGHCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for percona monitoring_and_management systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.

7.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-250

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • monitoring_and_management

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
monitoring_and_management

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-03: 1Mentions · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-17: 1Exploit Tool / Code · 2026-07-17: 1Active Exploitation · 2026-07-17: 1Technical Details · 2026-04-03: 1Technical Details · 2026-07-17: 104-0307-17
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-031
Disclosure1
2026-07-171
Active Exploitation1
Full discourse2 posts
  • Yusuf Can Çakır@Yusufcancakiir
    Active Exploitation

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The post describes a sophisticated fraud operation that actively weaponizes multiple high‑severity CVEs, employing custom exploitation scripts and AI‑assisted techniques to mass‑probe and compromise targets, while also running a large-scale card‑skimming infrastructure.

    215054404.8K
    1.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25212 - Critical An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data sourc... https://www.thehackerwire.com/vulnerability/CVE-2026-25212/ https://t.co/aMgR392s6u

    Post summary

    Percona PMM before version 3.7 has a privilege‑escalation flaw that allows pmm-admin users to exploit superuser privileges of an internal database user via the Add data source feature; no PoC, exploit code, patch, or active use reports are mentioned.

    0000056
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperconamonitoring_and_management---

Explore more