{"ip":"159.223.163.165","total_events":193,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"binaryedge","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (binaryedge).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"payload","label":"Sustained payload","detail":"32,750 bytes sent","bytes_sent":32750,"session_seconds":1,"persistent":false}},"first_seen":"2026-08-26T00:03:31","last_seen":"2026-09-21T01:47:06","events_24h":12,"events_7d":19,"geo":{"country_code":"US","country_name":"United States","region":"New Jersey","city":"North Bergen","lat":40.7964,"lon":-74.0203,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":"nyc1-10.chlorine.do.prod.binaryedge.ninja","known_scanners":["binaryedge","BinaryEdge"],"scanner_tag":{"key":"binaryedge","label":"BinaryEdge","category":"commercial","url":"https://www.binaryedge.io/"},"cve_matches":[{"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang"},{"cve_id":"CVE-2022-40684","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin"},{"cve_id":"CVE-2023-40044","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js"},{"cve_id":"CVE-2024-0012","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2026-1340","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp"},{"cve_id":"CVE-2020-3452","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"}],"malware":[],"top_ports":[{"port":4444,"proto":"tcp","label":"","count":79},{"port":1801,"proto":"tcp","label":"","count":47},{"port":6000,"proto":"tcp","label":"X11","count":47},{"port":4588,"proto":"tcp","label":"","count":12},{"port":4433,"proto":"tcp","label":"","count":7},{"port":8080,"proto":"tcp","label":"HTTP-alt","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i2511h2_b78ed14e2fd0_ab7e3b40a677","t13i311000_e8f1e7e78f70_d41ae481755e","t13i3112h1_e8f1e7e78f70_d339722ba4af"],"tls_ja3":["c12b4ccd5320bbb380ca1a9df90f771d","48eb9b1182293f55c0710654b7b12fc6","f20f35624b79af10f537cb4e1e40197e"],"ja4h":["op10nn0000_000000000000","ge11nn0300_dedeb29cc523","ge11nn0400_9c3956fad5da","ge10nn0000_000000000000"]},"fingerprint_peers":{"t13i2511h2_b78ed14e2fd0_ab7e3b40a677":79,"t13i311000_e8f1e7e78f70_d41ae481755e":927,"t13i3112h1_e8f1e7e78f70_d339722ba4af":45,"op10nn0000_000000000000":1460,"ge11nn0300_dedeb29cc523":81,"ge11nn0400_9c3956fad5da":1528,"ge10nn0000_000000000000":2363},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"],"timeline":[{"date":"2026-08-26","count":79},{"date":"2026-08-28","count":47},{"date":"2026-08-31","count":47},{"date":"2026-09-12","count":1},{"date":"2026-09-15","count":7},{"date":"2026-09-21","count":12}],"recent_events":[{"timestamp":"2026-09-21T01:47:06","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\t\u0012;Bo3�D�\u0001�si=�\u0012��\u0019�\u001a:�\u0011ɮ�<0�8��\u0000\u000f�N�\u0005�޷<oN\u0001����/��*\u001f\u000e�C\f�4]��PVf\u001a\u0011��ȣ\u0016+b��","payload_hex":"09123b426f33a244fd018673693dae12bbc619fd1a3af311c9aeda3c30bc38819e000fca4efb05c6deb73c6f4e01a28782f52f8eed2a1f0eb7430ca0345dbd805056661a11aff5c8a3162b62b1d7","method":"","user_agent":"","ja3":"","session":"cf288b9d-4d2f-4a4b-b6d5-43342a6eae03","seq":1,"duration_ms":100,"bytes_in":78,"bytes_out":15,"enriched":{"digest":"39ac89559e81aae7","strings":[";Bo3"]}},{"timestamp":"2026-09-21T01:47:04","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"����E�����������������������������������\u0004�\u0012�0�����������������������&�\u0001�\u000f���\u0006�����!���\u0002�&�\f�\u0001���\n�\u0003���������+�\u0012�\u0002���\u0003�\u0002��� �#�������������������","payload_hex":"bdff9eff45ff9effbdff9effa4ff86ffc4ffbeffc7ffdbffeeffd9ffedffa4ff9dffcfffd8ffe5ff04ff12ff30ffb1ffbdffe7ffe2ffddffdcffdeffc8ffccffbefff8ff26ff01ff0ffff5ff06fffffff7ff21ffdeff02ff26ff0cff01fff5ff0aff03ffb1ffe4ffdefff0ff2bff12ff02fff8ff03ff02fffaff20ff23ffcbffc1ff9effcdffbaffc3ffc9ff91ffadff","method":"","user_agent":"","ja3":"","session":"eff6d5a4-f1d6-49c4-a453-52706cb2363f","seq":1,"duration_ms":100,"bytes_in":144,"bytes_out":15},{"timestamp":"2026-09-21T01:47:02","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\u0001�\u0000\u0000\u0000\u0001,�:���H����Pq���S��:\u0017�3\u0014o)S}���bζ\u000b��7>\u0001�v��E�D���A���\t����)k�c\u0018]V�V�_\u0005T\u000bt�\u000b��w�M=[1�\u0006���g^�\u0001�K��>�k�����H��D�`k��e\u001c��{_LP\u0015�\u001e\u000e���J","payload_hex":"0182000000012cef3ae789fe48afacf8c15071d7c3e8538ad63a17d933146f29537dbbbb9762ceb60b9bb9373e01cf76aea045b644eae1ea41c4dbee09acfbf084296bbb63185d568556c55f05540b74c40bbeb577bc4d3d5b31e1069cfdd3675ee3019b4bd7fc3eff6baf9599fbdb48908b4488606b92f5651caabb7b5f4c5015851e0e8fddc54a","method":"","user_agent":"","ja3":"","session":"d851722d-3aaf-4def-a031-a99239f9af24","seq":1,"duration_ms":100,"bytes_in":136,"bytes_out":15,"enriched":{"digest":"fd9b9b7985b23a32","strings":["o)S}","M=[1","{_LP"]}},{"timestamp":"2026-09-21T01:46:59","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"batman","payload_hex":"6261746d616e","method":"","user_agent":"","ja3":"","session":"7aa0eae5-4c3d-44e3-9a3b-753f1e49d17d","seq":1,"duration_ms":100,"bytes_in":6,"bytes_out":15,"enriched":{"digest":"5c6d9edc3a951cda","strings":["batman"]}},{"timestamp":"2026-09-21T01:46:57","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"H\u0000\u0000\u0000tj��#D�+����l�\u0019׍�\u0018�J\u001en��xu[l�E\u001d-j��xL�r�\u0015\u0010u�%�Rtg\u0005fv�]%̀\f�Ϯ\u0000��fȍD�\t�","payload_hex":"48000000746aa89e2344982bcaf0a7bb6cc519d78db618ed4a1e6ec1f978755b6cf0451d2d6aecd4784cc972c9151075e02586527467056676865d25cc800ce8cfae00b5c066c88d44c509f4","method":"","user_agent":"","ja3":"","session":"423d5f12-d4a1-4643-8dc5-4929bf23fba9","seq":1,"duration_ms":100,"bytes_in":76,"bytes_out":15,"enriched":{"digest":"898fcda528e932c7","strings":["xu[l"]}},{"timestamp":"2026-09-21T01:46:55","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"145.ll|'|'|SGFjS2VkX0Q0OTkwNjI3|'|'|WIN-JNAPIER0859|'|'|JNapier|'|'|19-02-01|'|'||'|'|Win 7 Professional SP1 x64|'|'|No|'|'|0.7d|'|'|..|'|'|AA==|'|'|112.inf|'|'|SGFjS2VkDQoxOTIuMTY4LjkyLjIyMjo1NTUyDQpEZXNrdG9wDQpjbGllbnRhLmV4ZQ0KRmFsc2UNCkZhbHNlDQpUcnVlDQpGYWxzZQ==12.act|'|'|AA==","payload_hex":"3134352e6c6c7c277c277c5347466a5332566b583051304f546b774e6a49337c277c277c57494e2d4a4e4150494552303835397c277c277c4a4e61706965727c277c277c31392d30322d30317c277c277c7c277c277c57696e20372050726f66657373696f6e616c20535031207836347c277c277c4e6f7c277c277c302e37647c277c277c2e2e7c277c277c41413d3d7c277c277c3131322e696e667c277c277c5347466a5332566b44516f784f5449754d5459344c6a6b794c6a49794d6a6f314e545579445170455a584e72644739774451706a62476c6c626e52684c6d56345a51304b526d46736332554e436b5a6862484e6c44517055636e566c445170475957787a5a513d3d31322e6163747c277c277c41413d3d","method":"","user_agent":"","ja3":"","session":"b4679d9d-7323-454a-85ca-387ac883dc55","seq":1,"duration_ms":103,"bytes_in":280,"bytes_out":15,"enriched":{"digest":"9d2b2bbf7f0fce75","strings":["145.ll|'|'|SGFjS2VkX0Q0OTkwNjI3|'|'|WIN-JNAPIER0859|'|'|JNapier|'|'|19-02-01|'|'…"],"iocs":{"domains":["145.ll"]}}},{"timestamp":"2026-09-21T01:46:54","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"Gh0st�\u0000\u0000\u0000�\u0000\u0000\u0000x�KS``�����\u0006Č@�Q���\tH\u0007�\u0016�e&�*\u0004$&g+\u00182���00��rc\u0000\u0001\u0011��\u001f\\`&��K7�\u0019�n\f9�n\f;�\u000f3��sch�^�4'J����0Ñh]&��ΗS�A4L?2=�Ē�\u000b@�`\fT\u001f��]\nr\u000b\u0003#��\u0002~\u0006�\u0003+\u0018m�=�tC,C�L<<==\\�\u0019�\u0000� \u0002\u0000T�+\\","payload_hex":"4768307374ad000000e0000000789c4b53606098c3c0c0c006c48c40bc51968181094807a716956526a72a042426672b183294f6b03030aca87263000111a0821f5c602683c74b378619e56e0c39956e0c3b840f33ace8736368a85ecf34274a97a982e330c391685d2690f8ce9753cb41344c3f323de1c492860b40f5600c541faeaf5d0a720b0323a3dc027e0686032b186dc23dfd74432c43fd4c3c3c3d3d5c9d198800e520020054f52b5c","method":"","user_agent":"","ja3":"","session":"3c5da117-9a6d-4c8a-8937-5a8ba04b6698","seq":1,"duration_ms":100,"bytes_in":173,"bytes_out":15,"enriched":{"digest":"424a73c6483ebe99","strings":["Gh0st","KS``","$&g+","A4L?2=","tC,C","L<<==\\"]}},{"timestamp":"2026-09-21T01:46:52","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\u001b�հ]�ē�0�X�ڱ׬�n\u001d�\u001e\u001a3*��\u001d'��k���\nG\u0001�\u0001W\u001c�z\u001bOe�\u0005�aFCy\u0015sA\u0003\u0016����C�p�*�\u0019���b�v\u0007G�/��&o\u0006\u0015�@J\u0001z\u000e��3iBQ�Q\u0010�\u000f\u0007\u001c۔�b2M\"�� ��\u0001\u0012�Z�&e�\f�\rX'�\u0005�ͤGH\u0000/~s;`(&)�K_\u0002\u0002��\u0000\u0010���Y7���\u000bn��*#�L\r����\u0007�sz\u001cs�W��\b/��0*�\u0004~3E]�M�ؑ\b��Ց��ь��(�����\"eUY�E:I2_���\u001c\\�~�\nc~��rZ�/U���f�fic^.���yQ&�\u0003`��\u0013\u001f�\u0007�\f��7�A��7p��3�\u001a㏠\u001bLI&�R\u001emE\u0011�\r�����T�<Rm-<��\b�����\u001b\u0013�\u0017�:z��y���\u0006M\u0018/�\u0019e��>�\u0003\u0003�v�%ѳ*{\n\b�\u0001\u0002}QB�7\u0002��b�F\\\u0011w�H����!��<�Y��娅1��2�\u000b�s��\nsN��S\b;|�d\u0010s�\\i�Vq�ͫ]M��6\u0010��֒���\"\n��?���\u0011)�9��:\u0002\u001f����!�\u000b�v�9\u0014��\u0015;q�V���\u0011�x���Fv���_�!\u0010��C/��\u000f��\u0004������0��5�D","payload_hex":"1b84d5b05df4c493c530c2588cdab1d7acaf6e1de11e1a332a85b71d27b1c96bbff0bc0a4701e101571cdd7a1b4f65cf05b0614643791573410316acb9b0d943da709b2acc198acec262c2760747f22f94ea266f061582404a017a0e9cfd33694251995110e50f071cdb949362324d22e1e220eeb50112a85aaa2665f90c880d58279e05c9cda44748002f7e733b6028267f29b54b5f0202858f0010e485f95937a0f5e20b6e91eb2a23ef4c0da983d0ed07ea737a1c73e657d4d5082f82b5302af6047e33455dfb4de2d89108eaeed59196c3d18ca1ac28e093d6fcf422655559db453a49325fbc8de11c5cfb7ea80a637eafea725a912f55e6e29466e46669635e2ec2faad795126c5036086ee131f9207820cc8d537d241a38a3770a0f233b91ae38fa01b4c4926c7521e6d4511da0dbec5cbd8c454973c526d2d3ce28e0888cbe2f5f91b138e17cb3a7aebc479fefda2064d182fe81965f6ff3e900303de76da25d1b32a7b0a08c701027d5142f53702be8262c7465c11777fd148b1e5b2ff219ba03c94597fb6a9e5a88531f6a232a30bd9739da30a734ea7e753083b7cd4641073bd5c69f45671ebcdab5d4dbeab3610b98fd692c9dcda220ab1c63fb3a2d31129c239f0cb3a021ff3fce99f21f10bf076963914eb9e153b71a75696b2e811d778f9efe84676f2c1c65fa521109fab432f9e8f0fdbce048efc84ace9e830b3c2358444","method":"","user_agent":"","ja3":"","session":"673dc076-7e76-4800-a31c-8572f21b46c1","seq":1,"duration_ms":100,"bytes_in":518,"bytes_out":15,"enriched":{"digest":"2d739036b122bcbb","strings":["aFCy","3iBQ","b2M\"","/~s;`(&","~3E]","\"eUY","E:I2_","fic^.","<Rm-<","GH/~s;`(&"]}},{"timestamp":"2026-09-21T01:46:50","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"lv|'|'|VHJvamFuX0M0NkY2RTk=|'|'|MARK|'|'|user|'|'|2013-11-22|'|'||'|'|Win XP|'|'|No|'|'|0.6.4|'|'|..|'|'||'|'|[endof]","payload_hex":"6c767c277c277c56484a76616d467558304d304e6b593252546b3d7c277c277c4d41524b7c277c277c757365727c277c277c323031332d31312d32327c277c277c7c277c277c57696e2058507c277c277c4e6f7c277c277c302e362e347c277c277c2e2e7c277c277c7c277c277c5b656e646f665d","method":"","user_agent":"","ja3":"","session":"f2d26b29-e665-4123-ae11-bd239b97d033","seq":1,"duration_ms":100,"bytes_in":117,"bytes_out":15,"enriched":{"digest":"048dd147840ff571","strings":["lv|'|'|VHJvamFuX0M0NkY2RTk=|'|'|MARK|'|'|user|'|'|2013-11-22|'|'||'|'|Win XP|'|'…"]}},{"timestamp":"2026-09-21T01:46:48","port":4588,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"HELP\r\n","payload_hex":"48454c500d0a","method":"","user_agent":"","ja3":"","session":"ed35b44b-ad8d-472b-a8dd-c4fecdd25e44","seq":1,"duration_ms":100,"bytes_in":6,"bytes_out":15,"enriched":{"digest":"d6616dd899abc961","strings":["HELP"]}}],"http_methods":[{"method":"GET","count":94},{"method":"OPTIONS","count":4}],"distinct_ports_total":6,"top_paths":[{"path":"/","count":12,"ports":6},{"path":"/auth.html","count":2,"ports":2},{"path":"/nice%20ports%2C/Tri%6Eity.txt%2ebak","count":2,"ports":2},{"path":"/sonicui/7/sslvpn-portal/","count":2,"ports":2},{"path":"/secure/Dashboard.jspa","count":1,"ports":1},{"path":"/api/v2/cmdb/system/admin/admin","count":1,"ports":1},{"path":"/rdweb","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/mftp","count":1,"ports":1},{"path":"/webui/","count":1,"ports":1},{"path":"/wsman","count":1,"ports":1},{"path":"/Login.jsp","count":1,"ports":1},{"path":"/configurations","count":1,"ports":1},{"path":"/login.action","count":1,"ports":1},{"path":"/human.aspx","count":1,"ports":1}],"distinct_paths_total":84,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":79},{"value":"h2, http/1.1","count":7}],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"CVE-2018-13379","tag_type":"cve","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-13379"]},{"tag_id":"CVE-2022-40684","tag_type":"cve","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin","reference_urls":["https://github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py","https://securityonline.info/researchers-have-developed-cve-2022-40684-poc-exploit-code/","https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684","https://nvd.nist.gov/vuln/detail/CVE-2022-40684"]},{"tag_id":"CVE-2023-40044","tag_type":"cve","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js","reference_urls":["https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044","https://censys.com/cve-2023-40044/","https://www.progress.com/ws_ftp","https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/","https://www.theregister.com/2023/10/02/ws_ftp_update/"]},{"tag_id":"CVE-2024-0012","tag_type":"cve","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map","reference_urls":["https://security.paloaltonetworks.com/CVE-2024-0012","https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","https://nvd.nist.gov/vuln/detail/CVE-2024-0012"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2026-1340","tag_type":"cve","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM","https://nvd.nist.gov/vuln/detail/CVE-2026-1340"]},{"tag_id":"CVE-2020-3452","tag_type":"cve","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua","reference_urls":["https://twitter.com/aboul3la/status/1286012324722155525","http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html","http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html","http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html","http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]}],"data_as_of":"2026-09-21T10:42:58.737984+00:00"}