# T1190 Exploit Public-Facing Application

> As of 2026-10-05, T1190 (Exploit Public-Facing Application) appears in 958 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including APT28, Qilin, ShinyHunters; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 958 (525 critical, 348 high, 69 medium, 3 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 146
- **Detection rules:** 2364 (counts only; Blue tier and above)

## Key facts

- **ID:** T1190
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1190/

## Activity timeline

T1190 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 306 reports, and 955 of the 958 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1190 Exploit Public-Facing Application is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 958 of 2623 tracked threats (36.5%) to it; by severity that is 525 critical, 348 high, 69 medium, 3 low.

Threats that use T1190 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (504 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (428 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (411 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (398 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (372 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

146 tracked threat actors appear in the threats that use T1190; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (11), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (11), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (10), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (9), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (9).

## Mitigations

MITRE ATT&CK lists 8 mitigations for T1190.

- [M1016 Vulnerability Scanning](https://attack.mitre.org/mitigations/M1016/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1190, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 11
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 11
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 10
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 9
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 9
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 8
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 8
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 7
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 7
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 6

## Tracked threats

The 30 most recent of 958 tracked threats that use T1190.

- [Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…](https://intel.threadlinqs.com/threat/TL-2026-2912) — critical — 2026-10-04
- [CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2896) — high — 2026-10-04
- [TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…](https://intel.threadlinqs.com/threat/TL-2026-2889) — high — 2026-10-04
- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft…](https://intel.threadlinqs.com/threat/TL-2026-2874) — critical — 2026-10-03
- [Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to…](https://intel.threadlinqs.com/threat/TL-2026-2865) — critical — 2026-10-03
- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2860) — critical — 2026-10-03
- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…](https://intel.threadlinqs.com/threat/TL-2026-2854) — critical — 2026-10-03
- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection…](https://intel.threadlinqs.com/threat/TL-2026-2902) — critical — 2026-10-02
- [Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…](https://intel.threadlinqs.com/threat/TL-2026-2892) — high — 2026-10-02
- [Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)](https://intel.threadlinqs.com/threat/TL-2026-2876) — medium — 2026-10-02
- [City of Vicksburg, Mississippi shuts down systems after ransomware attack](https://intel.threadlinqs.com/threat/TL-2026-2862) — medium — 2026-10-02
- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)](https://intel.threadlinqs.com/threat/TL-2026-2846) — critical — 2026-10-02
- [Frontline Education data breach via exploited third-party software vulnerability exposes school district…](https://intel.threadlinqs.com/threat/TL-2026-2844) — high — 2026-10-02
- [CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490…](https://intel.threadlinqs.com/threat/TL-2026-2843) — critical — 2026-10-02
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks](https://intel.threadlinqs.com/threat/TL-2026-2830) — critical — 2026-10-01
- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)](https://intel.threadlinqs.com/threat/TL-2026-2823) — critical — 2026-10-01
- [Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild](https://intel.threadlinqs.com/threat/TL-2026-2820) — critical — 2026-09-30
- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)](https://intel.threadlinqs.com/threat/TL-2026-2816) — critical — 2026-09-30
- [WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)](https://intel.threadlinqs.com/threat/TL-2026-2813) — critical — 2026-09-30
- [Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…](https://intel.threadlinqs.com/threat/TL-2026-2805) — critical — 2026-09-30
- [Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)](https://intel.threadlinqs.com/threat/TL-2026-2793) — high — 2026-09-29

## Related CVEs

CVEs referenced by the tracked threats that use T1190, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)

## Detection coverage

Threadlinqs maintains 2364 detection rules mapped to T1190 (SPL 901, KQL 729, Sigma 734). Rule content is available to Blue tier accounts and above; this page shows counts only.

2364 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1190
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
