# T1499.004 Application or System Exploitation

> As of 2026-10-05, T1499.004 (Application or System Exploitation) appears in 74 tracked threats, first reported 2026-04-15 and most recently 2026-10-04, with linked actors including Handala Hack, UNK_MassTraction, Void Manticore; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 74 (36 critical, 28 high, 9 medium)
- **First seen:** 2026-04-15
- **Last seen:** 2026-10-04
- **Threat actors:** 3
- **Detection rules:** 219 (counts only; Blue tier and above)

## Key facts

- **ID:** T1499.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1499
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1499/004/

## Activity timeline

T1499.004 first appeared in tracked threats on 2026-04-15 and was most recently reported on 2026-10-04. The busiest month was 2026-09 with 26 reports, and 74 of the 74 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1499.004 Application or System Exploitation is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499). Threadlinqs maps 74 of 2623 tracked threats (2.8%) to it; by severity that is 36 critical, 28 high, 9 medium.

Threats that use T1499.004 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (49 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (40 threats), [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) (38 threats), [T1587.004 Exploits](https://intel.threadlinqs.com/technique/T1587.004) (29 threats), [T1588.005 Exploits](https://intel.threadlinqs.com/technique/T1588.005) (27 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1499.004; the most frequent are [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [UNK_MassTraction](https://intel.threadlinqs.com/actor/UNK_MassTraction) (1), [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1499.004.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1499.004, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Sensor Health — Host Status

## Threat actors using it

- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [UNK_MassTraction](https://intel.threadlinqs.com/actor/UNK_MassTraction) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1

## Tracked threats

The 30 most recent of 74 tracked threats that use T1499.004.

- [CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2896) — high — 2026-10-04
- [Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)](https://intel.threadlinqs.com/threat/TL-2026-2876) — medium — 2026-10-02
- [Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)](https://intel.threadlinqs.com/threat/TL-2026-2838) — critical — 2026-10-02
- [WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)](https://intel.threadlinqs.com/threat/TL-2026-2813) — critical — 2026-09-30
- [Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…](https://intel.threadlinqs.com/threat/TL-2026-2805) — critical — 2026-09-30
- [Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS…](https://intel.threadlinqs.com/threat/TL-2026-2849) — high — 2026-09-29
- [CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosd](https://intel.threadlinqs.com/threat/TL-2026-2746) — high — 2026-09-28
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)](https://intel.threadlinqs.com/threat/TL-2026-2682) — high — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…](https://intel.threadlinqs.com/threat/TL-2026-2662) — medium — 2026-09-26
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…](https://intel.threadlinqs.com/threat/TL-2026-2572) — high — 2026-09-18
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — critical — 2026-09-18
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — critical — 2026-09-18
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…](https://intel.threadlinqs.com/threat/TL-2026-2522) — critical — 2026-09-15
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively…](https://intel.threadlinqs.com/threat/TL-2026-2486) — critical — 2026-09-13
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — high — 2026-09-13
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE](https://intel.threadlinqs.com/threat/TL-2026-2440) — critical — 2026-09-10
- [Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…](https://intel.threadlinqs.com/threat/TL-2026-2340) — critical — 2026-09-05
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29

## Related CVEs

CVEs referenced by the tracked threats that use T1499.004, most frequent first.

- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-1218](https://intel.threadlinqs.com/cve/CVE-2025-1218)
- [CVE-2025-14181](https://intel.threadlinqs.com/cve/CVE-2025-14181)
- [CVE-2025-25249](https://intel.threadlinqs.com/cve/CVE-2025-25249)
- [CVE-2025-31718](https://intel.threadlinqs.com/cve/CVE-2025-31718)
- [CVE-2025-3450](https://intel.threadlinqs.com/cve/CVE-2025-3450)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2026-0310](https://intel.threadlinqs.com/cve/CVE-2026-0310)
- [CVE-2026-101891](https://intel.threadlinqs.com/cve/CVE-2026-101891)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-15681](https://intel.threadlinqs.com/cve/CVE-2026-15681)
- [CVE-2026-15682](https://intel.threadlinqs.com/cve/CVE-2026-15682)
- [CVE-2026-17545](https://intel.threadlinqs.com/cve/CVE-2026-17545)
- [CVE-2026-18145](https://intel.threadlinqs.com/cve/CVE-2026-18145)
- [CVE-2026-19478](https://intel.threadlinqs.com/cve/CVE-2026-19478)
- [CVE-2026-19489](https://intel.threadlinqs.com/cve/CVE-2026-19489)
- [CVE-2026-19490](https://intel.threadlinqs.com/cve/CVE-2026-19490)
- [CVE-2026-19650](https://intel.threadlinqs.com/cve/CVE-2026-19650)
- [CVE-2026-20349](https://intel.threadlinqs.com/cve/CVE-2026-20349)
- [CVE-2026-23918](https://intel.threadlinqs.com/cve/CVE-2026-23918)
- [CVE-2026-3039](https://intel.threadlinqs.com/cve/CVE-2026-3039)
- [CVE-2026-32746](https://intel.threadlinqs.com/cve/CVE-2026-32746)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)

## Detection coverage

Threadlinqs maintains 219 detection rules mapped to T1499.004 (SPL 75, KQL 71, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.

219 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499) — 127 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1499.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
