logo

Cisco SD-WAN 0-Day: What MSPs Should Do Now

ID: 7292d166-7eac-5d31-89ec-3bb1ea7c70f4

STIX ID: report--7292d166-7eac-5d31-89ec-3bb1ea7c70f4

Feed Name: WatchGuard Secplicity Blog

Threat Score
88/100

Date Published: 2026-03-10

Date Updated: 2026-05-01

Author: The Editor

...
...

This report reviews three high-risk themes: (1) an actively exploited CVSS 10.0 authorization-bypass in Cisco Catalyst SD-WAN controllers enabling privileged access and potential root persistence (attributed to a China-based actor); (2) a multi-package NPM supply-chain worm that harvests secrets, uses GitHub Actions for propagation, and contains AI-targeted prompt-injection and destructive failsafes; and (3) a coordinated developer-targeting campaign using fake job interviews hosted on Bitbucket that executes attacker JavaScript (via VS Code/workspace automation and other paths) to deploy in-memory loaders and backdoors — the report provides IOCs, hunting guidance, and operational mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.