CVE-2026-3587Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 14 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 13 mentions (2026-03-23); latest day: 1
  • 18 total mentions across 5 days

Deep dive

Activity timeline18 mentions / 5d
0371013Mentions · 2026-03-23: 13Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-04-15: 2Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-03-23: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-23: 3Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-23: 11Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-21: 103-2303-2403-2604-1504-21
Signal classification4 categories
Disclosure
950.0%
Patch
633.3%
General
211.1%
Active Exploitation
15.6%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-2313
Active Exploitation1Disclosure8General2Patch2
2026-03-241
Disclosure1
2026-03-261
Patch1
2026-04-152
Patch2
2026-04-211
Patch1
Full discourse18 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical 10.0 CVSS flaw in WAGO managed switches (CVE-2026-3587) allows unauthenticated remote takeover via an undocumented CLI backdoor. Update immediately. #WAGO #CyberSecurity #CVE #InfoSec #IndustrialSecurity #OTSecurity #Vulnerability #PatchAlert https://securityonline.info/critical-10-cvss-wago-managed-switch-backdoor-vulnerability-cve-2026-3587/ https://t.co/A1MVVzKqwh

    Post summary

    A critical 10.0 CVSS flaw (CVE‑2026‑3587) in WAGO managed switches allows unauthenticated remote takeover through an undocumented CLI backdoor; users are advised to update immediately.

    0110134976
    10.9K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 الكشف عن ثغرة حرجة (CVSS 10.0) من نوع Backdoor تؤثر على محولات WAGO تم الكشف عن ثغرة أمنية بالغة الخطورة (CVE-2026-3587) من نوع "Backdoor" غير موثق، تحمل تصنيف CVSS يبلغ 10.0، ضمن عدة نماذج من محولات WAGO المدارة. تستغل هذه الثغرة لتمكين السيطرة الكاملة على الشبكات الصناعية المعرضة للخطر. يؤدي هذا الخلل إلى تعريض البنية التحتية الحيوية لاختراق شامل. يُنصح المؤسسات التي تستخدم محولات WAGO بتحديد الأجهزة المتأثرة ومتابعة تحديثات الشركة المصنعة فور صدورها للتخفيف من هذا التهديد الفوري. 🔗 للمزيد: https://securityonline.info/critical-10-cvss-wago-managed-switch-backdoor-vulnerability-cve-2026-3587/

    Post summary

    A critical backdoor vulnerability (CVE‑2026‑3587) with a CVSS score of 10.0 affecting WAGO managed switches is disclosed, highlighting the risk of full system compromise and urging manufacturers to issue patches.

    0103079
    80 followersView on X
  • z3n@zench4n
    Patch

    * CVE-2026-4473: Remote code execution possible in Online Doctor Appointment System. Patch now! * CVE-2026-3587: Unauth'd CLI exploit. Lock down your systems!

    Post summary

    The message announces two CVEs with RCE and unauthenticated CLI exploitation, and stresses that a patch is available.

    1000020
    1.5K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-4606 | CVSS 10.0 🔴 CVE-2026-3587 | CVSS 10.0 🔴 CVE-2026-4567 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three CVEs with very high CVSS scores (10.0 and 9.8) and provides a link to a page where more details can be found.

    0001071
    5.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-3587 — CVSS 10/10 ██████████ An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/qEBwkAwNpJ

    Post summary

    The tweet announces CVE-2026-3587, a critical unauthrized remote CLI escape vulnerability, and urges users to apply the available patch.

    1000038
    9 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-3587: WAGO Industrial Managed Switch CLI Escape — Detection and Harden… "CISA warns unauthenticated attackers can escape the restricted CLI on WAGO…" 🔗 https://securityarsenal.com/blog/cve-2026-3587-wago-industrial-managed-switch-cli-escape-detection-and-hardening-guide #CyberSecurity #ThreatIntel #alerttriage #alertfatigue #socautomation

    Post summary

    CISA warns that unauthenticated attackers can escape the restricted CLI on WAGO Industrial Managed Switches, and a detection/hardening guide is referenced for mitigation.

    0000033
    11 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-3587: WAGO Industrial Managed Switches CLI Escape — Detection and Reme… "CISA has released ICS Advisory ICSA-26-085-01 regarding a critical security…" 🔗 https://securityarsenal.com/blog/cve-2026-3587-wago-industrial-managed-switches-cli-escape-detection-and-remediation-guide #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The post announces CISA's advisory on CVE‑2026‑3587 and links to a remediation guide, but does not provide PoC, exploit code, or evidence of active abuse.

    0000033
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Critical WAGO Switch CLI Escape: Patching Guide for CVE-2026-3587 "Industrial control systems (ICS) are the backbone of critical infrastructure, and the security of…" 🔗 https://securityarsenal.com/blog/critical-wago-switch-cli-escape-patching-guide-for-cve-2026-3587 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The tweet promotes a blog post that offers a patching guide for CVE-2026-3587, providing remediation instructions without discussing PoCs, exploit code, or active attacks.

    0000022
    10 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 OT security strikes again: WAGO switches had a CLI “escape” that could turn zero-auth access into full compromise. Disable SSH/Telnet now—because of course it’s that kind of bug. https://windowsforum.com/threads/wago-managed-switch-cli-escape-flaw-cve-2026-3587-patch-and-disable-ssh-telnet.407659/ #OtSecurity #NetworkHardening #FirmwareUpdates #IndustrialSwitches https://t.co/DQFxHNODd3

    Post summary

    The tweet warns that a CLI escape flaw in WAGO switches could allow unauthenticated full compromise, and advises disabling SSH/Telnet as a mitigation, with no mention of an active exploit or PoC.

    0000032
    1.0K followersView on X
  • Dr.Mashari@GMashari
    General

    📌 الكشف عن ثغرة حرجة (CVSS 10.0) من نوع Backdoor غير موثق تؤثر على محولات WAGO المدارة 🛡️ الفئة: ثغرة 📝 الملخص: تم الكشف عن ثغرة أمنية بالغة الخطورة (CVE-2026-3587) من نوع "Backdoor" غير موثق، تحمل تصنيف CVSS يبلغ 10.0، ضمن عدة نماذج من محولات WAGO المدارة. تستغل هذه الثغرة لتمكين السيطرة الكاملة على الشبكات الصناعية المعرضة للخطر. يؤدي هذا الخلل إلى تعريض البنية التحتية الحيوية لاختراق شامل. يُنصح المؤسسات التي تستخدم محولات WAGO بتحديد الأجهزة المتأثرة ومتابعة تحديثات الشركة المصنعة فور صدورها للتخفيف من هذا التهديد الفوري. 🗓️ تاريخ النشر: 23/03/2026 🔗 للمزيد: https://securityonline.info/critical-10-cvss-wago-managed-switch-backdoor-vulnerability-cve-2026-3587/

    Post summary

    The post announces CVE‑2026‑3587, a critically scored Backdoor vulnerability in WAGO managed switches, but provides no PoC, exploitation tool, patch, or evidence of active exploitation.

    00000105
    9.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3587 📊 Severity: 10.0 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3587 #CVE-2026-3587 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/4uJcPyUw8M

    Post summary

    An alert announces CVE-2026-3587 with a CVSS score of 10.0; no further technical, exploit, or patch details are provided.

    0000027
    111 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting WAGO Lean Managed Switch 852-1812 and other products (CVE-2026-3587) https://vuldb.com/?ctiid.352498

    Post summary

    The post alerts to detected elevated activity targeting WAGO Lean Managed Switches linked to CVE‑2026‑3587, indicating potential real‑world exploitation but without detailed technical or exploit information.

    0000050
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3587 CLI Prompt Bypass Vulnerability Enabling Unauthenticated Root Access in Linux Device https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3587

    Post summary

    The post announces CVE-2026-3587 as a CLI prompt bypass that permits unauthenticated root access on Linux, linking to a vulnerability detail page without providing PoC, exploit, or patch information.

    0000053
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3587 - Hidden CLI Function Allows Root Access Intel Report: https://ift.tt/jZL0q6y

    Post summary

    An alert announces CVE‑2026‑3587, highlighting a hidden CLI function that grants root access, with a link to an intel report but lacking details on exploits, patches, or active use.

    0000018
    290 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for WAGO Lean Managed Switch 852-1812 and other products (CVE-2026-3587) https://vuldb.com/?id.352498

    Post summary

    A severe vulnerability affecting WAGO Lean Managed Switch 852-1812 has been disclosed as CVE-2026-3587.

    0000061
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3587: CRITICAL] Beware! Cybersecurity risk: Unauthenticated attackers can exploit a hidden CLI function to access Linux OS as root, compromising the device. #CyberSecurity#cve,CVE-2026-3587,#cybersecurity https://cvefind.com/CVE-2026-3587

    Post summary

    The post announces CVE‑2026‑3587, a critical flaw that lets unauthenticated attackers use a hidden CLI to gain root access on Linux devices, linking to a CVE database entry.

    0000056
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3587 - Critical An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full... https://www.thehackerwire.com/vulnerability/CVE-2026-3587/ https://t.co/jwjJS5k4lX

    Post summary

    CVE-2026-3587 is a critical remote code execution vulnerability that allows unauthenticated attackers to escape a restricted CLI and gain root on Linux systems, as detailed in the linked advisory.

    0000035
    144 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3587: Hidden CLI Function Allows Root A... Hidden CLI functions in network gear are the ultimate foothold - WAGO switches bleeding root shells to anyone who knows ... https://zerodaysignal.com/vulnerability/CVE-2026-3587 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑3587, highlighting that hidden CLI functions in WAGO switches allow attackers to gain root shells, but offers no PoC, tool, or patch details.

    0000028
    162 followersView on X

Explore more