logo

The SysAid Zero-Day Vulnerability: CVE-2023-47246 | UpGuard

ID: aff8526c-a1f4-559f-aa9a-98bc47f0f630

STIX ID: report--aff8526c-a1f4-559f-aa9a-98bc47f0f630

Feed Name: UpGuard Blog

Threat Score
80/100

Date Published: 2025-01-17

Date Updated: 2026-05-01

...
...

SysAid on-premises contains a critical path traversal zero-day (CVE-2023-47246) actively exploited by the Lace Tempest threat actor to upload a Tomcat webshell, execute a Powershell-based loader (TurtleLoader), inject the GraceWire trojan into service executables, run Cobalt Strike, and enable possible data exfiltration and ransomware; SysAid and UpGuard advise immediate upgrade to version 23.3.36 and comprehensive compromise assessments alongside IOC and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.