| Date | Source | Article |
|---|---|---|
| 2026-06-24 | Kaspersky Securelist | StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2022-41040 |
Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2020-12812 | 9.8 Critical | Fortinet FortiOS Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the… |
| CVE-2018-13379 | 9.1 Critical | Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil… |
| CVE-2024-57727 | 9.1 Critical | SimpleHelp SimpleHelp SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary… |
| CVE-2022-41040 | 8.8 High | Microsoft Exchange Server Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which a… |
| CVE-2022-41082 | 8.0 High | Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vul… |
Extracted from the publication text. Each CVE links to its tracked detail page.
Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.