U.S. govt reveals top security flaws exploited by Chinese hackers since 2020

October 7, 2022

Top security agencies in the US have published the top security vulnerabilities exploited by the People’s Republic of China (PRC) hackers since 2020. NSA, CISA and FBI confirm once again that these Chinese-sponsored hackers are targeting U.S. and allied networks and technology companies in order to gain access and steal sensitive data.

Major flaws include: Apache Log4j (CVE-2021-44228) a remote code execution flaw; Pulse Connect Secure (CVE-2019-11510), an arbitrary file read flaw; GitLab CE/EE (CVE-2021-22205), a remote code execution bug; Atlassian (CVE-2022-26134), a remote code execution bug; Microsoft Exchange (CVE-2021-26855), a remote code execution bug; F5 Big-IP (CVE-2020-5902), a remote code execution flaw; VMware vCenter Server (CVE-2021-22005), an arbitrary file upload bug; Citrix ADC (CVE-2019-19781), a path traversal flaw; Cisco Hyperflex (CVE-2021-1407), a command line execution flaw; and Buffalo WSR (CVE-2021-20090), a relative path traversal flaw.

Others include Atlassian Confluence Server and Data Center (CVE-2021-26084), a remote code execution flaw; Hikvision Webserver (CVE-2021-36260), a command injection flaw; SitecoreXP (CVE-2021-42237), a remote code execution flaw; F5 Big-IP (CVE-2022-1388), a remote code execution flaw; Apache (CVE-2022-24112), an authentication bypass flaw; ZOHO (CVE-2021-40539), a remote code execution flaw; Microsoft (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) all remote code execution flaws; and Apache HTTP Server (CVE-2021-41773), a path traversal flaw.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

June 5, 2026 Security researchers have disclosed a new denial-of-service attack called HTTP/2 Bomb that can overwhelm major web servers more...

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn