logo

Thousands of Qlik Sense Servers Open to Cactus Ransomware

ID: aef27d7a-f54e-53e9-b55d-cb844d85bd36

STIX ID: report--aef27d7a-f54e-53e9-b55d-cb844d85bd36

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-04-26

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Nearly five months after Qlik disclosed CVE-2023-41266, CVE-2023-41265 and the subsequent bypass CVE-2023-48365, security teams observed the Cactus ransomware group exploiting these flaws to gain remote code execution in Qlik Sense; scans identified 5,205 internet-accessible Qlik Sense servers with 3,143 still vulnerable and at least 122 likely compromised, prompting Fox-IT, DIVD, ShadowServer and others to notify affected organizations and warn of a high likelihood of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.