Multiple Vulnerabilities in Internet-Facing Systems Targeting Hong Kong’s Education Sector
CSIRTS triage
- What
- Multiple vulnerabilities target internet-facing systems in Hong Kong’s education sector.
- Who is affected
- Systems in the education sector of Hong Kong.
- Urgency
- Remediation is urgent as these vulnerabilities are actively exploited.
- Action
- Conduct a thorough security assessment and apply necessary mitigations.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/multiple-vulnerabilities-in-internet-facing-systems-targeting-hong-kong-s-education-sector_20260724
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2020-25223EPSS puts this in the most-targeted tier (96.7% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2020-26919EPSS puts this in the most-targeted tier (57.5% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
- Exploitation likely imminentCVE-2020-7796EPSS puts this in the most-targeted tier (84.4% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2021-1497EPSS puts this in the most-targeted tier (99.9% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2021-31755EPSS puts this in the most-targeted tier (85.8% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2021-36380EPSS puts this in the most-targeted tier (97.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2022-26143EPSS puts this in the most-targeted tier (87.2% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Elevated exploitation riskCVE-2018-1151111.2% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 96% of all scored CVEs.
- Exploitation likely imminentCVE-2018-16167EPSS puts this in the most-targeted tier (74.7% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
- Exploitation likely imminentCVE-2018-17254EPSS puts this in the most-targeted tier (83.0% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2020-25223 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-26919 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7796 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-1497 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-31755 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-36380 | coverage & exploitation status | NVD · CVE.org |
| CVE-2022-26143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-11511 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-16167 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-17254 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-35713 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-1498 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-24139 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-32305 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedCVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerabilitycisa-kev
- criticalexploitedCVE-2021-36380: Sunhillo SureLine OS Command Injection Vulnerablitycisa-kev
- criticalexploitedCVE-2022-26143: MiCollab, MiVoice Business Express Access Control Vulnerabilitycisa-kev
- criticalexploitedCVE-2020-25223: Sophos SG UTM Remote Code Execution Vulnerabilitycisa-kev
- criticalexploitedCVE-2021-1497: Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerabilitycisa-kev
- criticalexploitedCVE-2020-26919: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerabilitycisa-kev
- criticalexploitedCVE-2021-31755: Tenda AC11 Router Stack Buffer Overflow Vulnerabilitycisa-kev
- criticalexploitedCVE-2021-1498: Cisco HyperFlex HX Data Platform Command Injection Vulnerabilitycisa-kev
More from HKCERT Security Bulletins
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownCitrix XenServer Multiple Vulnerabilities2026-07-30