On September 28, 2025, a significant surge in exploitation attempts targeting the Grafana path traversal vulnerability, CVE-2021-43798, was detected by GreyNoise. This vulnerability allows attackers to perform arbitrary file reads on vulnerable Grafana instances, posing a serious risk to organizations using the affected software. Over the course of a single day, GreyNoise observed 110 unique IP addresses attempting to exploit this flaw, all of which were classified as malicious. The majority of these IPs originated from Bangladesh, with 107 IPs traced to that country, while the remaining sources included China and Germany. Of the Bangladesh-based IPs, 105 specifically targeted endpoints in the United States, indicating a focused attack pattern. The destinations of the attacks were limited to three countries: the United States, Slovakia, and Taiwan, with the U.S. being the primary target. The attack traffic followed a consistent ratio across these countries, approximately 3:1:1 for the U.S., Slovakia, and Taiwan, respectively. Analysis of the TCP and HTTP fingerprints revealed that multiple tools were used in the attacks, but all were directed at the same set of targets, suggesting a coordinated campaign rather than random, opportunistic exploitation. Two notable IP addresses from China, both belonging to CHINANET-BACKBONE, were highlighted for their activity on the day of the surge. These IPs were only active on September 28 and were not observed before or after this date, further supporting the theory of a coordinated, time-bound operation. The exploitation activity had been relatively quiet in the months leading up to this event, making the sudden spike particularly noteworthy. GreyNoise's Global Observation Grid (GOG) was instrumental in detecting and analyzing the surge, providing valuable intelligence on the geographic and technical characteristics of the attack. The convergence of attack patterns, source geographies, and tooling points to shared tasking or a common target list among the attackers. Organizations using Grafana are advised to ensure that their systems are patched against CVE-2021-43798 and to monitor for suspicious activity from the identified malicious IPs. The incident underscores the ongoing threat posed by unpatched vulnerabilities in widely used open-source software. Security teams should remain vigilant for similar coordinated exploitation attempts, especially following periods of low activity. The rapid mobilization of a large number of malicious IPs in a single day demonstrates the attackers' ability to coordinate and execute targeted campaigns efficiently. This event highlights the importance of global threat intelligence sharing and proactive vulnerability management. The attack serves as a reminder that even older vulnerabilities can become the focus of renewed exploitation efforts. Organizations should review their exposure to Grafana and implement appropriate network defenses to mitigate the risk of similar attacks.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
GreyNoise published research describing the coordinated Grafana exploitation attempts and drawing attention to the renewed abuse of CVE-2021-43798. The report documented the observed activity and warned defenders to investigate exposed systems.
GreyNoise observed a coordinated surge of exploitation attempts against Grafana path traversal vulnerability CVE-2021-43798 on 28 September 2025. The activity was notable enough to be highlighted as a distinct campaign targeting exposed Grafana instances.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecurityonline.info
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.