SSF Cyber Defence Digest – 7 January 2026: Active Exploitation and Critical Exposure


SSF Cyber Defence Digest

Issue Date: 7 January 2026
Reporting Period: 7 December 2025 – 7 January 2026

Cyber threat alerts for security professionals to assess emerging risks, evaluate potential exposure, and investigate further using official advisories and trusted technical sources.

⚠ React2Shell Rapidly Exploited by China-Linked Threat Actors

Vulnerability Level: 🔴 Critical
Incident Summary: Active exploitation affected React and Next.js Server Functions, enabling remote code execution and web-shell deployment.
Attack Vector: CVE-2025-55182 | Remote Code Execution | Internet-facing applications
Potential Impact: Server compromise | Credential theft | Persistent access | Lateral movement
Defence: Patch affected applications, review exposed servers, enable EDR, and check for indicators of compromise.

⚠ Google Chrome Zero-Day Exploited in the Wild

Vulnerability Level: 🔴 Critical
Incident Summary: Google released an update for an actively exploited vulnerability affecting Chrome and Chromium-based browsers.
Attack Vector: CVE-2025-14174 | Memory corruption | Browser exploitation
Potential Impact: Endpoint compromise | Remote code execution | Session theft
Defence: Update managed browsers, verify patch compliance, and review endpoint alerts.

⚠ Fortinet SSO Authentication Bypass

Vulnerability Level: 🔴 Critical
Incident Summary: Authentication bypass vulnerabilities affected FortiCloud Single Sign-On and exposed enterprise deployments.
Attack Vector: CVE-2025-59718 / CVE-2025-59719 | SAML manipulation | Authentication bypass
Potential Impact: Administrative access | Configuration theft | Unauthorised access
Defence: Apply vendor updates, restrict management interfaces, and review authentication and configuration-export logs.

⚠ Legacy Fortinet MFA Bypass Remains Targeted

Vulnerability Level: 🟠 High
Incident Summary: Continued exploitation of an older Fortinet flaw highlighted the risk of unpatched legacy infrastructure.
Attack Vector: CVE-2020-12812 | Authentication bypass | Weak MFA configuration
Potential Impact: Unauthorised access | VPN compromise | Appliance takeover
Defence: Verify patch status, audit VPN and MFA settings, and restrict management access.

⚠ Critical n8n Workflow Automation Vulnerability

Vulnerability Level: 🔴 Critical
Incident Summary: A critical vulnerability affected exposed n8n workflow services and could allow access to server resources and workflow secrets.
Attack Vector: CVE-2026-21858 | Remote Code Execution | Exposed workflow services
Potential Impact: Server compromise | Credential exposure | Workflow manipulation
Defence: Upgrade affected deployments, restrict internet exposure, and review credentials, webhooks, and workflow activity.

Shilpa Sayura Cyber Defence Reseach Lab


Editorial Note: This digest provides an intelligence starting point. Confirm product exposure and consult official vendor advisories before taking remediation action.