← Back to Feed

Multiple Vulnerabilities in Internet-Facing Systems Targeting Hong Kong’s Education Sector

CVE-2018-11511CVE-2018-16167CVE-2018-17254CVE-2020-25223CVE-2020-26919CVE-2020-35713CVE-2020-7796CVE-2021-1498CVE-2021-24139CVE-2021-31755CVE-2021-32305CVE-2021-36380CVE-2022-26143

July 24, 2026 · HKCERT · Severity: HIGH

HKCERT reports that threat actors are targeting internet-facing systems of Hong Kong's education sector by exploiting multiple vulnerabilities. Successful exploitation can lead to remote code execution, denial of service, or security restriction bypass. Organizations should patch affected systems such as ASUSTOR ADM, LogonTracer, and JCK Editor.

Key Takeaways

  • Threat actors are scanning for vulnerabilities in internet-facing systems of Hong Kong's education sector.
  • Exploitable vulnerabilities include remote code execution, denial of service, and security restriction bypass.
  • Affected technologies include ASUSTOR ADM, LogonTracer, and JCK Editor for Joomla, among others.
☕ Buy a Coffee