A Two-Packet RCE On Port 49 With No CVE — And Chinese State Actors Already There
The AAA protocol that decides who administers every switch and router just got a clean pre-auth exploit, and the one tool you'd rely on to find it cannot see it.
Elttam's bug matters because of the ecosystem rot around it. Cisco abandoned TACACS+ in the late 1990s. Only two codebases survive: the Shrubbery Networks version, now quietly patched, and a Facebook fork that was archived years ago and will never receive a fix. Neither had shipped an update in over five years, and Elttam reports waiting roughly nine months for any maintainer reply. Critically, no CVE was assigned — so your vulnerability scanners, patch-management dashboards and default SOC alerting will not flag it. The most dangerous exposure on your network is invisible to the exact tooling you bought to catch it.
Why this is not hypothetical
Elttam warns that two Chinese cyber-espionage crews — Salt Typhoon and Fire Ant — have already targeted TACACS servers over the past two years for persistence and lateral movement against telecoms, precisely because compromising the AAA server hands them administrative access to every device that authenticates against it. The exploit needs only two packets plus offline cracking of the protocol's weak encryption, and works over the internet or LAN when the attacker has a path to the central server. Publishing a clean exploit path lowers the barrier for everyone else. One caveat worth carrying to leadership: the edge-device variant is less reliable because vendors implement the protocol differently, but the direct-to-server path is clean — and that is the one your central AAA servers expose.
It lands as the patch window collapses
TACACS+ is not alone. WordPress CVE-2026-87902, an unauthenticated path-traversal-to-RCE affecting every release in the past decade, was under mass exploitation within hours of its patch, with honeypots capturing the chain (pearcmd.php inclusion, a write to /tmp, then a GitHub-hosted uploader). Roundcube CVE-2026-48842 is exploited in the wild against unpatched installs. The connective pattern: speed is measured in hours, and your scanner is not the source of truth for what to fix first.
Patch what you can, isolate what you can't, and stop trusting your scanner to find the thing with no CVE.
The move
Because there is no CVE, this will fall out of an automated remediation program unless you create a manual asset-tracking entry for it. Contain first, patch second: restrict port 49 so it is unreachable from untrusted networks, then hunt your AAA logs for the state-actor TTPs that predate the public exploit.
What to do
Have the network team inventory every TACACS+ server and client relationship today, restrict port 49 at the perimeter and between segments, patch Shrubbery Networks deployments immediately, and open a dated migration plan off the unpatchable Facebook fork tracked as a manual asset entry.
Task the threat-hunting team this sprint with hunting network AAA infrastructure for Salt Typhoon and Fire Ant TTPs — anomalous auth and device-admin escalation staged from TACACS servers — since state-actor use predates the public exploit.