Last Update: 08/01/2026 at 1:00 PM EST

Attackers Exploit Exposed Enterprise Gateways

Coverage from BleepingComputer, The Record, and others

Articles

14

Active Days

151

The Topic

Attackers Exploit Exposed Enterprise Gateways topic image

Attackers are exploiting or actively probing vulnerabilities in internet-facing email platforms, secure access gateways, AI development infrastructure, mobile devices, and network appliances. The incidents show how flaws in systems that bridge users, applications, and internal networks can enable credential theft, session compromise, code execution, data exposure, or malware delivery. CISA directives and vendor patches underscore the need to prioritize exposed assets and investigate for compromise, although exploitation status and actor attribution remain uneven across cases.

First Article: 02/23/26

Latest Article: 07/23/26

Summary

  • Roundcube flaws were used against university mail servers in the United States and Canada to steal credentials and deploy backdoors.
  • Ivanti Sentry gateways were reportedly backdoored soon after a critical command-injection flaw was patched, despite the vendor initially reporting no known exploitation.
  • CISA ordered federal agencies to patch actively exploited vulnerabilities in Langflow, DarkSword-targeted iOS devices, and other enterprise products.
  • Zimbra’s critical stored XSS flaw can expose session data, account settings, and mailbox information when users open crafted emails.
  • Exposed NetScaler ADC and Gateway appliances create a large potential attack surface for session-token theft and user-session compromise.
  • Attack objectives include espionage, credential theft, data access, compute and cloud-key abuse, and delivery of follow-on malware.
  • The evidence mixes confirmed exploitation, active scanning or attempts, and unconfirmed risk, making incident verification important alongside patching.

History

07/23/2026

The story tightens around a few more clearly characterized exploitation cases, especially Ivanti Sentry backdooring and CISA’s active exploitation directives, while also adding clearer distinction between confirmed exploitation and unconfirmed risk. The framing shifts from a broad roundup of exposed systems to a more cautionary emphasis on verification and patch prioritization.

07/23/2026

The story is now anchored by specific exploitation cases and affected targets, rather than a general pattern of active vulnerability abuse. It also broadens more clearly into AI workflows and mobile-device compromise, while adding concrete evidence of compromise such as credential theft, backdoors, and likely gateway intrusion.

Full History

Featured

Timeline: 151 Days

Feb 23Mar 23Apr 20May 18Jun 15Jul 13

Additional Articles

⭐⭐⭐

BleepingComputer / Sergiu Gatlan06-11-2026
Shadowserver reported next-day backdooring and exploitation attempts involving Ivanti Sentry CVE-2026-10520 after Ivanti released patch versions in 2026.
BleepingComputer / Sergiu Gatlan07-08-2026
CISA set a federal patch deadline for Langflow CVE-2026-55255 after in-the-wild IDOR exploitation exposed other users' AI agent flows.
The Record / James Reddick07-23-2026
U.S., U.K., and European agencies warned in 2026 that Laundry Bear used zero-click phishing against Zimbra webmail, exploiting CVE-2025-66376 for email and credential theft attempts.
BleepingComputer / Sergiu Gatlan03-23-2026
CISA ordered U.S. federal civilian agencies to patch three iOS vulnerabilities actively exploited through DarkSword, after researchers connected the chain to data-theft malware campaigns.
BleepingComputer / Sergiu Gatlan03-25-2026
Citrix patched NetScaler ADC and NetScaler Gateway vulnerabilities CVE-2026-3055 and CVE-2026-4368 to reduce risks of session token theft and session mix-ups on internet-facing identity deployments.
BleepingComputer / Bill Toulas03-29-2026
watchTowr and ShadowServer reported in-the-wild exploitation of CVE-2026-3055 in Citrix NetScaler identity gateway appliances that can expose authenticated administrative session IDs.
BleepingComputer / Sergiu Gatlan03-30-2026
CISA ordered U.S. Federal Civilian agencies to patch Citrix NetScaler appliances by April 2 after CVE-2026-3055 was added to the Known Exploited Vulnerabilities Catalog.
BleepingComputer / Sergiu Gatlan04-08-2026
CISA ordered U.S. federal agencies to patch Ivanti EPMM by April 11 after CVE-2026-1340 showed active zero-day exploitation.

⭐️⭐️

BleepingComputer / Sergiu Gatlan02-23-2026
CISA orders federal agencies to patch Roundcube vulnerabilities by March 13 in the United States.
BleepingComputer / Sergiu Gatlan03-16-2026
CISA warns Wing FTP Server users in the United States to patch active vulnerabilities in May 2025 to prevent remote code execution and data disclosure.
BleepingComputer / Bill Toulas03-20-2026
CISA directed Federal Civilian Executive Branch agencies to patch Cisco Secure Firewall Management Center vulnerability CVE-2026-20131 by March 22 due to ransomware exploitation in the wild.