Multiple vulnerabilities in CyberArk and HashiCorp Vaults enable remote takeover
Summary
Hide β²
Show βΌ
Cybersecurity researchers discovered 14 vulnerabilities in CyberArk and HashiCorp products that allow remote attackers to bypass authentication, escalate privileges, and execute arbitrary code. These flaws, collectively named Vault Fault, affect CyberArk Secrets Manager, Self-Hosted, Conjur Open Source, and HashiCorp Vault. The vulnerabilities enable attackers to extract enterprise secrets and tokens without valid credentials. The vulnerabilities were disclosed in May 2025 and have since been patched in the latest versions of the affected products. The most severe issues allow for remote code execution and root token theft. The flaws include authentication bypasses, impersonation, privilege escalation bugs, and code execution pathways. Attackers can exploit these vulnerabilities to take over the vault and turn security features into ransomware vectors.
Timeline
-
09.08.2025 08:15 π° 1 articles
Vulnerabilities in CyberArk and HashiCorp Vaults disclosed and patched
Cybersecurity researchers discovered 14 vulnerabilities in CyberArk and HashiCorp products that allow remote attackers to bypass authentication, escalate privileges, and execute arbitrary code. The vulnerabilities, collectively named Vault Fault, were disclosed in May 2025 and have since been patched in the latest versions of the affected products. The most severe issues allow for remote code execution and root token theft. The flaws include authentication bypasses, impersonation, privilege escalation bugs, and code execution pathways. Attackers can exploit these vulnerabilities to take over the vault and turn security features into ransomware vectors.
Show sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
Information Snippets
-
The vulnerabilities affect CyberArk Secrets Manager, Self-Hosted, and Conjur Open Source, as well as HashiCorp Vault.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The flaws include authentication bypasses, impersonation, privilege escalation bugs, and code execution pathways.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The most severe vulnerabilities allow for remote code execution and root token theft.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The vulnerabilities were disclosed in May 2025 and have been patched in the latest versions of the affected products.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The flaws can be exploited to turn security features into ransomware vectors.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The vulnerabilities can be chained together to achieve unauthenticated access and run arbitrary commands.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The vulnerabilities include CVE-2025-49827, CVE-2025-49831, CVE-2025-49828, CVE-2025-6000, and CVE-2025-5999.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
-
The vulnerabilities have been patched in CyberArk Secrets Manager and Self-Hosted 13.5.1 and 13.6.1, CyberArk Conjur Open Source 1.22.1, and HashiCorp Vault Community Edition 1.20.2 or Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
First reported: 09.08.2025 08:15π° 1 source, 1 articleShow sources
- CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials β thehackernews.com β 09.08.2025 08:15
Similar Happenings
HybridPetya Ransomware Bypasses UEFI Secure Boot via CVE-2024-7344
A new ransomware strain, HybridPetya, has been discovered. It resembles the Petya/NotPetya malware and can bypass UEFI Secure Boot using the CVE-2024-7344 vulnerability. HybridPetya encrypts the Master File Table (MFT) on NTFS-formatted partitions and installs a malicious EFI application on the EFI System Partition. The ransomware has two main components: a bootkit and an installer. The bootkit handles encryption and decryption processes, displaying fake CHKDSK messages to deceive victims. The ransom note demands $1,000 in Bitcoin, with a wallet receiving $183.32 between February and May 2025. HybridPetya exploits a remote code execution vulnerability in the Howyar Reloader UEFI application, allowing it to bypass Secure Boot. The variant uses a specially crafted file named 'cloak.dat' to load the bootkit binary. Microsoft revoked the vulnerable binary in January 2025. ESET's telemetry data indicates no evidence of HybridPetya being used in the wild, suggesting it may be a proof-of-concept (PoC). The ransomware incorporates characteristics from both Petya and NotPetya, including the visual style and attack chain. It drops several files into the EFI System Partition, including configuration, validation, and encryption progress tracking files. The ransom note provides a 32-character key for decryption and system restoration upon payment. Indicators of compromise for HybridPetya are available on a GitHub repository. Microsoft fixed CVE-2024-7344 with the January 2025 Patch Tuesday updates.
CVE-2025-5086 in DELMIA Apriso Exploited in the Wild
A critical deserialization vulnerability (CVE-2025-5086) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management (MOM) software is being actively exploited. The flaw, with a CVSS score of 9.0, affects versions from Release 2020 through Release 2025. The vulnerability allows for remote code execution, and exploitation attempts have been observed originating from an IP address in Mexico. The attacks involve sending a malicious HTTP request with a Base64-encoded payload. The payload decodes to a Windows executable identified as "Trojan.MSIL.Zapchast.gen," a spyware capable of capturing user activities and sending collected information to attackers. DELMIA Apriso is used in production processes for digitalizing and monitoring, including scheduling production, quality management, resource allocation, warehouse management, and integration between production equipment and business applications. The flaw impacts critical industries such as automotive, aerospace, electronics, high-tech, and industrial machinery. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog and is advising federal agencies to apply necessary updates by October 2, 2025.
Akira Ransomware Exploits SonicWall SSL VPN Flaws and Misconfigurations
The Akira ransomware group has been actively exploiting vulnerabilities and misconfigurations in SonicWall SSL VPN devices to gain initial access to networks. This campaign has seen increased activity since late July 2025, targeting organizations globally, including those in Australia. The attacks leverage a year-old flaw (CVE-2024-40766) and misconfigured LDAP settings to bypass access controls and facilitate ransomware deployment. The threat actors use a combination of brute-forcing credentials, exploiting default configurations, and leveraging the Virtual Office Portal to configure multi-factor authentication (MFA) with valid accounts. These tactics allow them to bypass security measures and gain unauthorized access to networks. SonicWall has confirmed that recent SSLVPN activity is related to CVE-2024-40766, not a zero-day vulnerability. The affected firewall versions include specific models of Gen 5, Gen 6, and Gen 7 devices. Organizations are advised to update to firmware version 7.3.0 or later, rotate passwords, enforce MFA, mitigate the SSLVPN Default Groups risk, and restrict Virtual Office Portal access to trusted/internal networks to mitigate risks.
Cursor AI editor autoruns malicious code in repositories
A flaw in the Cursor AI editor allows malicious code in repositories to autorun on developer devices. This vulnerability can lead to malware execution, environment hijacking, and credential theft. The issue arises from Cursor disabling the Workspace Trust feature from VS Code, which prevents automatic task execution without explicit user consent. The flaw affects one million users who generate over a billion lines of code daily. The Cursor team has decided not to fix the issue, citing the need to maintain AI and other features. They recommend users enable Workspace Trust manually or use basic text editors for unknown projects. The flaw is part of a broader trend of prompt injections and jailbreaks affecting AI-powered coding tools.
Critical SessionReaper vulnerability patched in Adobe Commerce and Magento Open Source
Adobe has patched a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms, dubbed SessionReaper. This flaw, with a CVSS score of 9.1, could allow unauthenticated attackers to take control of customer accounts via the Commerce REST API. The patch was released on September 9, 2025, following an emergency notification to selected customers on September 4, 2025. Adobe Commerce on Cloud customers were already protected by a WAF rule deployed as an interim measure. The vulnerability is considered one of the most severe in the platform's history, with potential for widespread exploitation. Administrators are advised to apply the patch immediately, as it disables certain internal Magento functionalities that may affect custom or external code. The affected versions include Adobe Commerce 2.4.9-alpha2 and earlier, 2.4.8-p2 and earlier, 2.4.7-p7 and earlier, 2.4.6-p12 and earlier, 2.4.5-p14 and earlier, and 2.4.4-p15 and earlier. The affected versions also include Adobe Commerce B2B 1.5.3-alpha2 and earlier, 1.5.2-p2 and earlier, 1.4.2-p7 and earlier, 1.3.4-p14 and earlier, and 1.3.3-p15 and earlier. The affected versions include Magento Open Source 2.4.9-alpha2 and earlier, 2.4.8-p2 and earlier, 2.4.7-p7 and earlier, 2.4.6-p12 and earlier, and 2.4.5-p14 and earlier. The Custom Attributes Serializable module versions 0.1.0 to 0.4.0 are also affected.