Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

2026-08-25T01:23:23Zc4ace2042460178d45a7a35e71a88ac2432bbfe8c8295c29d3bf94060d789e17
AWSAndroidCISACalixGS7-XGSMicrosoft-TeamsNAT-bypassSAMLSynkLoaderToxicPandaWordPressZimbraactive-exploitationauthentication-bypasscloud-securitycredential-exposuredata-breachminiOrangephishingport-forwardingproxy-botnetroutersocial-engineeringvulnerability

What happened

BleepingComputer security feed highlighting active and emerging threats, including an unpatched Calix GS7 XGS router vulnerability enabling unauthenticated remote NAT bypass and port forwarding, active exploitation of a Zimbra Collaboration Suite flaw requiring urgent patching, WordPress miniOrange SAML authentication bypass attacks, ToxicPanda Android malware, Android vehicle head-unit proxy botnets, Teams phishing delivering SynkLoader, exposed AWS credentials, and social-engineering incidents. The most urgent items involve actively exploited vulnerabilities and flaws that can enable account

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c4ace2042460178d45a7a35e71a88ac2432bbfe8c8295c29d3bf94060d789e17
Enrichment time
2026-08-25T01:23:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.