Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

01e3dce00ea45829bd9f6a583004976ac63973a0

TLP:CLEAR
Active

SHA-1 Hash

Description

Cisco Talos tracks active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager, allowing remote attackers to obtain administrative privileges. The exploitation is attributed to UAT-8616, a sophisticated threat actor previously involved in similar attacks. Additionally, multiple threat clusters have been exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since March 2026, following public release of proof-of-concept code by ZeroZenX Labs. Post-compromise activities include deployment of various webshells, including XenShell, Godzilla, and Behinder variants, along with cryptocurrency miners, red team frameworks like Sliver and AdaptixC2, and credential stealers. Ten distinct threat clusters have been identified, each utilizing different malicious tooling and infrastructure. Affected systems require immediate patching and security measures.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Pattern Type
STIX
Confidence
75%
Valid From
May 18, 2026 04:51
Total Sightings
0
Added
May 18, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 01e3dce00ea45829bd9f6a583004976ac63973a0

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.