Activity timeline
T1499.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 26 reports, and 74 of the 74 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1499.004 Application or System Exploitation is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1499 Endpoint Denial of Service. Threadlinqs maps 74 of 2623 tracked threats (2.8%) to it; by severity that is 36 critical, 28 high, 9 medium.
Threats that use T1499.004 most often also use T1190 Exploit Public-Facing Application (49 threats), T1595.002 Vulnerability Scanning (40 threats), T1588.006 Vulnerabilities (38 threats), T1587.004 Exploits (29 threats), T1588.005 Exploits (27 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1499.004; the most frequent are Handala Hack (1), UNK_MassTraction (1), Void Manticore (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1499.004.
Data sources
Telemetry that can reveal T1499.004, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Sensor Health — Host Status
Threat actors using it
Tracked threats
The 30 most recent of 74 tracked threats that use T1499.004.
- CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Cataloghigh
- Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)medium
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)critical
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)critical
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…critical
- Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS…high
- CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosdhigh
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)high
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…high
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalogcritical
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Rootcritical
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…critical
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively…critical
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalationhigh
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…critical
- CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCEcritical
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…critical
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)critical
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
Detection coverage
Threadlinqs maintains 219 detection rules mapped to T1499.004 (SPL 75, KQL 71, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1499 Endpoint Denial of Service — 127 tracked threats at the technique level.