MITRE ATT&CK technique

T1190

Exploit Public-Facing Application

About this technique

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Read the full ATT&CK description

Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve Exploitation for Defense Evasion or Exploitation for Client Execution.

If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container.

This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies.

Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar)

For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)

TA0001
Curated mapping

Curated incident relationships

These associations come from maintained incident records. The recorded confidence is shown when the source record provides it.

5 items
Heuristic association

Daily items linked through predicted CVEs

A Daily item appears here when it mentions a CVE whose triage artifact predicts this technique. This is not a verified ATT&CK mapping.

3 items
Heuristic association

Predicted CVE associations

These backfilled or model-produced candidates come from the current triage artifact. They are informational, not official MITRE mappings.

10 items
Predicted
CVE-2026-15409
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-16232
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-16723 · source severity CRITICAL
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-27577
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-45659 · source severity HIGH
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-48618 · source severity HIGH
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-58644 · source severity CRITICAL
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-60137 · source severity MEDIUM
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-63030 · source severity CRITICAL
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.
Predicted
CVE-2026-63077 · source severity CRITICAL
Backfilled: CVE mentioned in Daily brief. Evidence: not component-matched; treat as informational until verified.