SPACEBEARS

RANSOMWARE

Confirmed CVEs (4)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2026-48027 CRITICAL nrwl nx-console 9.8 CVE-2026-50751 CRITICAL checkpoint Quantum Security Gateway 9.3 CVE-2023-21529 HIGH Microsoft Exchange Server 2019 Cumulative Update 12 8.8 CVE-2024-1708 HIGH ConnectWise ScreenConnect 8.4

Predicted CVEs (12) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2024-1709 CRITICAL ConnectWise ScreenConnect predicted 10.0 CVE-2026-48027 CRITICAL nrwl nx-console predicted 9.8 CVE-2026-50751 CRITICAL checkpoint Quantum Security Gateway predicted 9.3 CVE-2021-26855 CRITICAL Microsoft Exchange Server 2016 Cumulative Update 19 predicted 9.1 CVE-2021-34473 CRITICAL Microsoft Exchange Server 2013 Cumulative Update 23 predicted 9.1 CVE-2020-0688 HIGH Microsoft Exchange Server 2013 predicted 8.8 CVE-2022-41080 HIGH Microsoft Exchange Server 2016 Cumulative Update 23 predicted 8.8 CVE-2022-41040 HIGH Microsoft Exchange Server 2013 Cumulative Update 23 predicted 8.8 CVE-2023-21529 HIGH Microsoft Exchange Server 2019 Cumulative Update 12 predicted 8.8 CVE-2024-1708 HIGH ConnectWise ScreenConnect predicted 8.4 CVE-2022-41082 HIGH Microsoft Exchange Server 2013 Cumulative Update 23 predicted 8.0 CVE-2021-31207 MEDIUM Microsoft Exchange Server 2013 Cumulative Update 23 predicted 6.6