Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

89.125.244.51

TLP:CLEAR
Active

IPv4 Address

Description

Cisco Talos tracks active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager, allowing remote attackers to obtain administrative privileges. The exploitation is attributed to UAT-8616, a sophisticated threat actor previously involved in similar attacks. Additionally, multiple threat clusters have been exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since March 2026, following public release of proof-of-concept code by ZeroZenX Labs. Post-compromise activities include deployment of various webshells, including XenShell, Godzilla, and Behinder variants, along with cryptocurrency miners, red team frameworks like S... | Shodan InternetDB; ports: 22; software: cpe:/a:openbsd:openssh:9.6p1, cpe:/o:canonical:ubuntu_linux

Sightings (0)

No sightings recorded yet

Details

Name / Label
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Pattern Type
STIX
Confidence
75%
Valid From
May 18, 2026 04:51
Total Sightings
0
Added
May 18, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 89.125.244.51

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.