2026-08-21NOTABLECERT Polska discloses 13 ATutor flaws against an end-of-life product; one is pre-auth to administrator, and no fix is coming
Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
cve · CVE-2026-64960 single-source-national-cert
Coverage
1
first 2026-08-21 → last 2026-08-21
Latest activity
2026-08-21
CERT Polska discloses 13 ATutor flaws against an end-of-life product; one is pre-auth to administrator, and…
Peak priority
notable
1 notable
Targets
education
sectors: education, public-sector · regions: europe
Sources cited
1
1 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-64960, newest first. Check the date before acting on an older one.
- Inventory any ATutor instance across education and research estates and take it off the public internet; there is no patched version for any of the thirteen flaws and none is coming, so exposure reduction or decommissioning is the only remediation available.2026-08-21CVE-2026-64961 +12
Defender insights
What each entry about CVE-2026-64960 tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
- DiscoveryFile and Directory Discovery
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-21/atutor-13-cves-eol-no-fix-unauthenticated-admin-takeover · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-21/atutor-13-cves-eol-no-fix-unauthenticated-admin-takeover · ATT&CK page ↗
Discovery TA0007
T1083File and Directory Discovery×1
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-21/atutor-13-cves-eol-no-fix-unauthenticated-admin-takeover · ATT&CK page ↗
Entries about Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- ATutor×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a×1
Where this entity is cited
Source distribution
- cert.pl1 (100%)