# netty vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 5 netty CVEs, 1 in the CISA Known Exploited Vulnerabilities catalog, linked to 2 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 netty CVEs published between 2023-10-15 and 2026-07-15. The busiest month was 2026-07 (4 new CVEs). 1 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked netty CVEs.

- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487) — HIGH 7.5 · KEV · EPSS 100% · 2023-10-10
- [CVE-2026-56819](https://intel.threadlinqs.com/cve/CVE-2026-56819) — HIGH 7.5 · EPSS 0.6% · 2026-07-21
- [CVE-2026-56817](https://intel.threadlinqs.com/cve/CVE-2026-56817) — HIGH 8.3 · EPSS 0.6% · 2026-07-21
- [CVE-2026-59921](https://intel.threadlinqs.com/cve/CVE-2026-59921) — MEDIUM 5.7 · EPSS 0.3% · 2026-07-28
- [CVE-2026-56820](https://intel.threadlinqs.com/cve/CVE-2026-56820) — HIGH 7.4 · 2026-07-21

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 1 distinct netty product is affected. The most frequently affected:

- netty — 5 CVEs

## Threat activity

2 tracked threat campaigns reference netty products or exploit netty CVEs:

- [Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)](https://intel.threadlinqs.com/threat/TL-2026-2489) — CRITICAL — 2026-09-13
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01

## How to prioritise netty patching

This order follows the data Threadlinqs holds for netty, not a generic severity checklist:

- 1 of 5 netty CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487).
- Outside KEV, the highest EPSS scores are [CVE-2026-56819](https://intel.threadlinqs.com/cve/CVE-2026-56819) (0.6%), [CVE-2026-56817](https://intel.threadlinqs.com/cve/CVE-2026-56817) (0.6%), [CVE-2026-59921](https://intel.threadlinqs.com/cve/CVE-2026-59921) (0.3%).
- 0 CVEs score Critical and 4 High on CVSS v3 (maximum 8.3, average 7.3); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/netty
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
