logo

China's Volt Typhoon Exploits Zero-Day in Versa's SD-WAN Director Servers

ID: fa6aaff1-b89e-5fc4-b366-3c0f3b573e98

STIX ID: report--fa6aaff1-b89e-5fc4-b366-3c0f3b573e98

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-08-27

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Volt Typhoon actors have been exploiting a zero-day (CVE-2024-39717) in Versa Director (pre-22.1.4) to upload a bespoke web shell, "VersaMem," that captures plaintext credentials and loads in-memory Java modules; exploitation has been active since at least June against managed service, ISP, and IT victims, prompting Versa patches, mitigation guidance, and CISA listing the flaw in its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.