Security Briefing | June 24, 2026 - Cisco SSRF Flaw Exploited, FortiBleed Escalates to 430,000 Firewalls, New Mistic Backdoor Tied to Ransomware
A critical SSRF vulnerability in Cisco Unified Communications Manager is under active exploitation following public proof-of-concept release. The FortiBleed campaign has escalated dramatically, now linked to over 430,000 compromised FortiGate firewalls and 110 million harvested credentials. Meanwhile, a new backdoor called Mistic has been tied to ransomware access broker KongTuke, which feeds access to groups including Qilin, Akira, and Black Basta.
By EACA Summit Content Team

1. Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited After PoC Release
Threat actors are actively exploiting CVE-2026-20230, a critical SSRF vulnerability in Cisco Unified Communications Manager and Unified CM SME, after a proof-of-concept (PoC) was made public. The flaw allows unauthenticated remote attackers to perform arbitrary file writes, potentially leading to root access. Cisco released patches in early June 2026, but exploitation has been observed in the wild.
Verified Facts
- CVE-2026-20230 is a critical SSRF vulnerability in Cisco Unified CM and Unified CM SME with a CVSS score of 8.6
- Cisco confirmed a PoC was available when patches were announced in early June 2026
- Active exploitation has been reported by multiple sources including BleepingComputer and SecurityWeek
Evidence
- CVE-2026-20230
- Cisco advisory (patches released early June 2026)
Impact
Organizations using Cisco Unified Communications products are at immediate risk of compromise. The vulnerability can be exploited remotely without authentication, enabling attackers to gain root access and potentially pivot within the network. Immediate patching is critical.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. FortiBleed Campaign Escalates: 110 Million Credentials Harvested From 430,000 FortiGate Firewalls
The FortiBleed campaign, previously reported in the tens of thousands of affected devices, has escalated dramatically. A Russian-speaking initial access broker has been conducting this large-scale credential-harvesting operation since February 2026, now targeting over 430,000 FortiGate firewalls globally and reportedly harvesting 110 million credentials through brute-forcing and custom tool deployment.
Verified Facts
- The campaign is attributed to a Russian-speaking initial access broker driven by financial gain
- Over 430,000 FortiGate firewalls have been targeted since February 2026
- The operation involves credential harvesting, brute-forcing, and custom tool deployment
- 110 million credentials have been collected according to reports
Evidence
- FortiGate firewall telemetry
- IAB attribution by threat intelligence firms
Impact
This massive credential harvesting operation provides adversaries with extensive access to networks protected by FortiGate firewalls. Organizations using FortiGate should enforce strong authentication, monitor for brute-force attempts, and review access logs for signs of compromise. The harvested credentials could enable ransomware deployment and data exfiltration at scale.
Confidence Level: High
The Hacker News | BleepingComputer
3. Mistic Backdoor Linked to Ransomware Access Broker KongTuke

A new backdoor named Mistic has been discovered in financially motivated attacks targeting insurance, education, IT, and professional services sectors. The malware is linked to the initial access broker KongTuke (also known as Woodgnat), which provides access to ransomware groups including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Mistic enables persistent access and data theft.
Verified Facts
- Mistic is a new backdoor observed in attacks since at least early 2026
- Targeted sectors include insurance, education, IT, and professional services
- The backdoor is linked to initial access broker KongTuke (Woodgnat)
- KongTuke provides access to multiple ransomware families: Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta
Evidence
- Malware analysis reports from BleepingComputer and SecurityWeek
- Attribution to KongTuke by threat intelligence
Impact The Mistic backdoor represents a significant threat as it provides initial access for multiple ransomware operations. Organizations in targeted sectors should enhance endpoint detection, monitor for unusual network activity, and review access broker tactics. The link to multiple ransomware families increases the risk of data encryption and extortion.
Confidence Level: High
BleepingComputer | SecurityWeek
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



