logo

Cisco zero-day under ongoing attack by persistent threat group

ID: 3eb06ed8-3bd8-52f9-8757-31c6182cda04

STIX ID: report--3eb06ed8-3bd8-52f9-8757-31c6182cda04

Feed Name: CyberScoop

Threat Score
92/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Matt Kapko

...
...

Attackers exploited a critical authentication-bypass zero-day (CVE-2026-20182, CVSS 10) in Cisco Catalyst SD-WAN Controller/Manager — attributed to UAT-8616 and tied to prior Cisco edge vulnerabilities — enabling full administrative control across on-premises, cloud, and FedRAMP deployments; Cisco released patches and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.