Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
ID: 730a4014-ff7f-5d33-8ed1-372ed2ffa25c
STIX ID: report--730a4014-ff7f-5d33-8ed1-372ed2ffa25c
Feed Name: Cisco Talos
Cisco Talos reports active exploitation of multiple Cisco Catalyst SD‑WAN vulnerabilities: CVE‑2026‑20182 is being exploited in the wild by a sophisticated actor tracked as UAT‑8616 for authentication bypass and privilege gain, while separate clusters exploited CVE‑2026‑20133/20128/20122 to deploy JSP webshells (XenShell, Godzilla, Behinder), backdoors (AdaptixC2, Sliver, Nim-based implants), XMRig miners, credential stealers, and other tooling; the report enumerates ten intrusion clusters, dozens of IOCs (IPs, hashes, C2s), and provides patching and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
