Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!

Global
Using ELK & interested in automating ingestion of our threat intel for your network/constituency via our API? We have introduced an ECS logging script for our intelligence reports. This script uses Redis to queue events for Logstash. Check it out at github.com/The-Shadowserver-…
1
14
57
14,615
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): shadowserver.org/what-we-do/… Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA. Tree map stats: dashboard.shadowserver.org/s…
1
4
8
2,568
These should not be publicly accessible on the Internet due to potential vulnerabilities, such as the recent CVE-2026-67277 nvd.nist.gov/vuln/detail/cve… You can find all our MikroTik detections in Device ID report shadowserver.org/what-we-do/… (around 3M daily): dashboard.shadowserver.org/s…
1
1
3
1,019
For MikroTik with SSH enabled, check out our Accessible SSH reporting (shadowserver.org/what-we-do/…), with the tag 'mikrotik' dashboard.shadowserver.org/s… - just over 119K seen daily currently Background: cert.pl/en/posts/2026/09/vul…
1
2
614
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on @CISACyber KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/s… Tracker: dashboard.shadowserver.org/s…
1
5
6
1,974
IP data in Vulnerable HTTP reporting tagged 'cve-2026-86218': shadowserver.org/what-we-do/… 218 out of 1399 seen in total. This is one week after exploitation activity was first reported publicly. Patch info: documentation.n-able.com/N-c… Background on incidents: huntress.com/blog/n-able-vul…
1
770
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @GreyNoiseIO. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: dashboard.shadowserver.org/s…
1
10
13
2,344
Compromised Website Report: shadowserver.org/what-we-do/… Thank you to @GreyNoiseIO for the share! Background with info about the AI-orchestrated campaign behind the compromises (includes IOCs): greynoise.io/blog/ai-orchest…
1
1
1
529
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-s… for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US (16K) World Map: dashboard.shadowserver.org/s…
1
4
7
1,477
No CVEs have been issued meaning the vulnerabilities are essentially invisible to the security community limiting an effective response. We tag the raw IP data shared 'vulnerable-plex' in Vulnerable HTTP reporting: shadowserver.org/what-we-do/… Tracker: dashboard.shadowserver.org/s…
1
1
1,034
Running an outdated Plex Media Server? Patch! Dashboard Tree Map view: dashboard.shadowserver.org/s…
1
420
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/sept…. As discovered by @CERT_Polska_en cert.pl/en/posts/2026/09/vul… unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
1
20
66
7,375
At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check). IP data shared daily in Accessible SSH reporting shadowserver.org/what-we-do/… tagged 'mikrotik' & Device Identification reports: shadowserver.org/what-we-do/…
1
1
4
1,286
Exploitation is reported in the wild. Review for compromise and patch!
1
1
872
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: dashboard.shadowserver.org/s…
1
5
7
2,540
Daily IP data now in our Vulnerable HTTP reporting, tagged 'cve-2026-82078' & 'cve-2026-81578': shadowserver.org/what-we-do/… Tree map view: dashboard.shadowserver.org/s… NVD entry: nvd.nist.gov/vuln/detail/cve… nvd.nist.gov/vuln/detail/cve… Patch info: papercut.com/kb/Main/securit…
1
1
2
704
Make sure to install Emergency Patch (Release 3) - but assume compromise. Background on PaperCut incidents: huntress.com/blog/papercut-a… Detection based on Nuclei template by darses - github.com/projectdiscovery/… #CyberCivilDefense
2
1
435
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: shadowserver.org/what-we-do/… At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
1
4
9
1,771
Dashboard World Map view stats: dashboard.shadowserver.org/s… Dashboard Tree Map stats: dashboard.shadowserver.org/s… NVD entry: nvd.nist.gov/vuln/detail/cve… MS advisory: msrc.microsoft.com/update-gu… Daily IP data tagged 'cve-2026-62911' See also @ncsc_nl advisory: ncsc.nl/alerts/ernstige-kwet…
1
614