{"id":54597,"date":"2026-05-14T13:52:35","date_gmt":"2026-05-14T13:52:35","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=54597"},"modified":"2026-05-14T13:52:35","modified_gmt":"2026-05-14T13:52:35","slug":"ongoing-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=54597","title":{"rendered":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-14T18:05:08&#8243;,&#8221;description&#8221;:&#8221;* Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.\\n  * Successful exploitation of CVE-2026-20182 allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.\\n  * The exploitation of CVE-2026-20182 appears to have been limited so far and Talos clusters this activity under UAT-8616 with high confidence.\\n  * Talos is also aware of a series of threat actors, distinct from UAT-8616, that have been observed to be exploiting a different, previously disclosed set of vulnerabilities, in a new way than previously identified, beginning March 2026 &#8211; specifically CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122. It is important to note that those vulnerabilities are distinct from and pre-date CVE-2026-20182. Cisco released software updates and a security advisory addressing those vulnerabilities in February 2026, strongly recommending customers to upgrade.\\n  * We have identified multiple clusters of post-compromise activity, beginning March 2026, associated with the exploitation of CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 that deployed webshells and other malicious tooling, described in this post.\\n  * We observed the vast majority of this exploitation involved the use of ZeroZenX labs&#8217; proof-of-concept and accompanying JSP-based webshell which we track as \\&#8221;XenShell.\\&#8221;\\n\\n\\n\\n* * *\\n\\n## UAT-8616 in-the-wild (ITW) exploitation of CVE-2026-20182\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/threat-advisory.jpg)\\n\\nTalos is aware of the active, in-the-wild (ITW) exploitation of CVE-2026-20182 in Cisco Catalyst SD-WAN Controller and Manager, that allows log in to the affected system as an internal, high-privileged, non-root user account. Talos clusters the exploitation of this vulnerability and subsequent post-compromise activity under UAT-8616, whom we assess is a highly sophisticated cyber threat actor. UAT-8616 previously exploited a similar vulnerability in Cisco Catalyst SD-WAN Controller, CVE-2026-20127 to gain unauthorized access to SD-WAN systems.\\n\\nUAT-8616 performed similar post-compromise actions after successfully exploiting CVE-2026-20182, as was observed in the exploitation of CVE-2026-20127 by the same threat actor. UAT-8616 attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges. Our findings indicate that the infrastructure used by UAT-8616 to carry out exploitation and post-compromise activities also overlaps with the Operational Relay Box (ORB) networks that Talos monitors closely.\\n\\nCustomers are strongly advised to follow the guidance and recommendations published in Cisco&#8217;s Security Advisory on CVE-2026-20182. Customer support is also available by initiating a TAC request. Please refer to the Recommendations and Detection Guidance section for additional coverage information. We also recommend referring to Rapid7&#8217;s disclosure on CVE-2026-20182 for additional details.\\n\\n## In-the-wild (ITW) exploitation of CVE-2026-20133, CVE-2026-20122, and CVE-2026-20128\\n\\nTalos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device. Cisco released software updates and a security advisory addressing these vulnerabilities in February 2026. Following the public release of proof-of-concept code exploiting these vulnerabilities by ZeroZenX Labs in March, we observed the exploitation of the unpatched systems from March to April 2026.\\n\\nTalos has observed several other threat clusters, separate from UAT-8616, leveraging publicly available proof-of-concept exploit code to deploy webshells to affected systems. Following successful exploitation, the webshells would allow the attacker to execute bash commands on the affected system.\\n\\nThe vast majority of observed exploitation attempts involved the use of the ZeroZenX Labs proof-of-concept code and accompanying JavaServer Pages (JSP) shell, which we are calling \\&#8221;XenShell.\\&#8221; However, we observed several other JSP-based webshell variants, which are outlined below.\\n\\n_Note: The CVE referenced in the ZeroZenX Labs proof-of-concept is incorrectly attributed to_ _CVE-2026-20127_ _. Talos &#8216; analysis indicates that the targeted CVEs in the proof-of-concept are in-fact CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122._\\n\\nSo far, Talos has observed the following clusters of malicious activity being conducted post successful exploitation of CVE-2026-20133, CVE-2026-20122, and CVE-2026-20128: Cluster #1 to Cluster #10.\\n\\n### Cluster 1\\n\\nThis cluster has been actively exploiting CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 since at least March 6, 2026. Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename \\&#8221;20251117022131.jsp\\&#8221;. This variant is associated with a publicly available GitHub project.\\n\\nThe following IPs were used to carry out the exploit and subsequently interact with the shell:\\n\\n  * 38.181.52[.]89\\n  * 89.125.244[.]33\\n  * 89.125.244[.]51\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-deb361d2-0c87-407c-8fb4-08515c3a6aeb.png)Figure 1. Tas9er Godzilla shellcode deployed in Cluster #1.\\n\\n### Cluster 2\\n\\nThis cluster has been actively exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since at least March 10, 2026. Following their exploitation, the threat actor deployed a variant of the Behinder webshell under the filename \\&#8221;conf.jsp\\&#8221;. This variant has been modified to only use Base64 for encoding, as opposed to AES encryption commonly observed in other variants.\\n\\nThe IP \\&#8221;71.80.85[.]135\\&#8221; was used to carry out the exploit and interact with the shell.\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-2102a1a7-59e5-4cb0-9655-f5d040c4cfb7.png)Figure 2. Behinder webshell deployed in Cluster #2.\\n\\n### Cluster 3\\n\\nThis cluster has been actively exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since at least March 4, 2026. Following successful exploitation, the threat actor deployed XenShell under the name \\&#8221;sysv.jsp\\&#8221;, before returning hours later to deploy a variant of the Behinder webshell under the filename \\&#8221;sysinit.jsp\\&#8221;.\\n\\nThe IP \\&#8221;212.83.162[.]37\\&#8221; was used to carry out the exploit and interact with the shell.\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-aed13c93-08fb-48c7-a75c-42d4e2da8f45.png)Figure 3. Behinder webshell deployed in Cluster #3.\\n\\n### Cluster 4\\n\\nThis cluster has been actively exploiting CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 since at least March 3, 2026. Following successful exploitation, the threat actor deployed a variant of the Godzilla webshell under the filename \\&#8221;vmurnp_ikp.jsp\\&#8221;.\\n\\nThe following IPs are attributed to this cluster:\\n\\n  * 38.60.214[.]92\\n  * 65.20.67[.]134\\n  * 104.233.156[.]1\\n  * 194.233.100[.]40\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-f1acdf08-ff24-4985-8261-a7466198daa1.png)Figure 4. Godzilla webshell deployed in Cluster #4.\\n\\n### Cluster 5\\n\\nTalos observed the deployment, beginning March 13, 2026, of a malware agent compiled off the publicly available AdaptixC2 red team framework. The filename was \\&#8221;systemd-resolved\\&#8221; and the agent&#8217;s command and control (C2) is \\&#8221;194[.]163[.]175[.]135:4445\\&#8221;.\\n\\nThe authors have changed the default TCP banner for the sample from \\&#8221;AdapticC2 server\\&#8221; to \\&#8221;shadowcore\\&#8221;. Hosted on Contabo GmbH, this is likely a VPS. As of March 28, 2026, this C2 IP, \\&#8221;194[.]163[.]175[.]135\\&#8221; hosted:\\n\\n  * A Mythic C2 server on port 7443, along with a Mythic C2 server certificate with serial number: fece5b954e69b2c6a8d0a1029631a0d7\\n  * Another AdaptixC2 server on port 31337\\n  * An open SSH service on port 22, likely for administration of server\\n\\n\\n\\n### Cluster 6\\n\\nIn another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename \\&#8221;CWan\\&#8221;. The Sliver sample&#8217;s C2 is \\&#8221;mtls:\/\/23.27.143[.]170:443\\&#8221;.\\n\\n### Cluster 7\\n\\nIn this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script from the remote location \\&#8221;83.229.126[.]195\\&#8221;.\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-30689ca1-e62c-48c8-8549-45f764a97a34.png)Figure 5. Download and startup script for XMRig.\\n\\nThis IP, residing in Hong Kong, is also a known C2 server for Cobalt Strike.\\n\\n### Cluster 8\\n\\nActivity observed in Cluster 8 began as early as March 10, 2026. This cluster consisted of a few key malicious tools. The first tool is KScan, an asset mapping tool, that can port scan, TCP fingerprint, capture banners for specified assets, and obtain as much port information as possible without sending more packets. It can perform automatic brute-force cracking and brute-force RDP. The tool&#8217;s filename and Go packages have been renamed to \\&#8221;QScan\\&#8221; by the authors, but it is essentially the same implementation as the open-source GitHub version.\\n\\nThe second tool, named \\&#8221;agent1\\&#8221;, is a Nim-based implant. It is most likely based on the open-source tools, Nimplant, but is further modified to include:\\n\\n  * Additional commands\/capabilities, such as cd to directories; cat files; download and upload files; execute files using bash; and collect system information such as username, hostname, hwid, process listings, etc.\\n  * C2 endpoints for communication, registration\/check-ins, obtain tasks, provide results, and more:\\n    * \/api\/v1\/handshake\\n    * \/api\/v1\/results\\n    * \/api\/v1\/payloads\\n    * \/api\/v1\/exfiltrate\\n    * \/api\/v1\/tasks\\n    * \/api\/v1\/init\\n  * An RSA public key to be used by the agent to communicate with the C2 hosted on \\&#8221;hxxp:\/\/13[.]62[.]52[.]206:5004\\&#8221;.\\n\\n\\n\\nThis tool was downloaded and executed post-compromise from the remote location \\&#8221;replit[.]dev\\&#8221;:\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-950b2cf7-7052-4283-b7c5-3ff4c3821498.png)Figure 6. Download and startup script for the Nim-based implant.\\n\\nThe attackers executed this command on the compromised system while connected from the source IP \\&#8221;79[.]135[.]105[.]208\\&#8221;. This is likely a ProtonVPN node.\\n\\nReplit is an AI platform that facilitates building applications using AI. It is therefore likely that the backdoor was created with the help of AI to resemble Nimplant&#8217;s functionality with the additional capabilities and deviations listed above.\\n\\n### Cluster 9\\n\\nIn this cluster, since at least March 17, 2026, Talos observed the deployment of an XMRig miner and a peer-based proxying and tunneling tool.\\n\\nThis tool, gsocket, is a peer-based proxying and tunneling tool that allows peers to connect to each other within the Global Socket Relay Network (GSRN). GSRN allows peers to connect to each other using node IDs, which are unique 16-byte identifiers for nodes with the network.\\n\\nThis sample obtains the peer or C2 node to connect to by reading and Base58 decoding the accompanying \\&#8221;defunct[.]dat\\&#8221; file. The C2 peer ID is:\\n    \\n    \\n    78 c4 a2 37 56 27 7b b7 de 20 06 76 34 d2 63 c9  \\n    \\n\\nThe tool is activated by placing a malicious command in the .profile file:\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-0e5a9bc6-5972-4712-9d68-e31fc019883a.png)\\n\\nThis decodes to:\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-e68d4b40-40f1-486d-833e-7790193a9d4e.png)\\n\\n**XMRig Miner**\\n\\nAccompanying gsocket was a Monero miner and its scripts and configuration files. The miner is also activated via the user profile (.profile):\\n    \\n    \\n    \/tmp\/moneroocean\/miner.sh &#8211;config=\/tmp\/moneroocean\/config_background.json \\u003e\/dev\/null 2\\u003e\\u00261\\n    \\n\\nThe \\&#8221;miner.sh\\&#8221; will find all processes named XMRig, kill them, and then start its own copy of XMRig:\\n\\n![Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities](https:\/\/storage.ghost.io\/c\/af\/a0\/afa04ee3-414f-4481-8d23-7e7c146f192e\/content\/images\/2026\/05\/data-src-image-66f5c5b6-d9d2-441f-8e1b-b7740140ea01.png)\\n\\n### Cluster 10\\n\\nThis cluster of activity, since at least Mar 13, 2026, consisted of a credential stealer deployed along with accompanying scripts. The main script, named \\&#8221;loot_run.sh\\&#8221;, attempted to obtain:\\n\\n  * The admin user&#8217;s hashdump\\n  * JSON Web Tokens (JWT) key chunks that are used for REST API authentication\\n  * AWS credentials for vManage: AccesKeyId, SecretAccessKey and Token\\n\\n\\n\\nTwo other helper scripts were also deployed in this cluster to check if the current user could escalate to root. The scripts contained a hardcoded password and used it to execute the command `su root -c id`. The output is checked for the string \\&#8221;uid=0(root)\\&#8221; to verify successful escalation.\\n\\n## Recommendations and detection guidance\\n\\nCustomers are strongly advised to follow the guidance and recommendations published in Cisco&#8217;s Security Advisory on CVE-2026-20182. Customer support is also available by initiating a TAC request. Talos strongly recommends that customers and partners using Cisco Catalyst SD-WAN technology follow the steps outlined in this advisory to help protect their environments. We also recommend referring to Rapid7&#8217;s disclosure on CVE-2026-20182 for additional details.\\n\\nSnorts SIDs for CVE-2026-20182 are: 66482 &#8211; 66483\\n\\nPlease refer to the official Cisco Security Advisory on CVE-2026-20133, CVE-2026-20122, and CVE-202128 for the latest information regarding affected products, Indicators Of Compromise (IOCs), and mitigation steps.\\n\\nSnort SIDs for CVE-2026-20133: 66468 &#8211; 66469\\n\\nSnort SIDs for CVE-2026-20122: 66461 &#8211; 66462\\n\\nSnort SIDs for CVE-2026-20128: 66468 &#8211; 66469\\n\\nSnort SIDs for the threats detailed in Clusters #1 through 10 are:\\n\\n  * Snort2: 66200, 66201, 66202\\n  * Snort3: 301461, 301462, 66252\\n\\n\\n\\nClamAV signatures for the malicious tooling associated with these clusters:\\n\\n  * Unix.Tool.QScanCrack-10059958\\n  * Unix.Backdoor.NimPlant-10059957\\n  * Unix.Tool.GSocket-10059956\\n  * Unix.Backdoor.JSPZapLoot-10059955\\n  * Unix.Backdoor.GopherRAT-10059941\\n  * Unix.Backdoor.JSPZap-10059944\\n  * Unix.Backdoor.JSPZapExcEnc-10059945\\n  * Unix.Backdoor.GopherRAT-10059941\\n\\n\\n\\n## IOCs\\n\\nIOCs for the Clusters detailed above are also available in our GitHub repository here.\\n\\n### Cluster 1\\n\\n  * 38.181.52[.]89\\n  * 89.125.244[.]33\\n  * 89.125.244[.]51\\n\\n\\n\\n### Cluster 2\\n\\n  * 71.80.85[.]135\\n\\n\\n\\n### Cluster 3\\n\\n  * 212.83.162[.]37\\n\\n\\n\\n### Cluster 4\\n\\n  * 38.60.214[.]92\\n  * 65.20.67[.]134\\n  * 104.233.156[.]1\\n  * 194.233.100[.]40\\n\\n\\n\\n### Cluster 5 &#8211; AdaptixC2\\n\\n  * f6f8e0d790645395188fc521039385b7c4f42fa8b426fd035f489f6cda9b5da1\\n\\n\\n\\n### Cluster 5 &#8211; AdaptixC2 C2 server\\n\\n  * 194[.]163[.]175[.]135:4445\\n\\n\\n\\n### Cluster 5 &#8211; AdaptixC2 C2 IP\\n\\n  * 194[.]163[.]175[.]135\\n\\n\\n\\n### Cluster 6 &#8211; Sliver\\n\\n  * 02654acfb21f83485393ba8b14bd8862b919b9ec966fc6768f6aac1338a45ee8\\n\\n\\n\\n### Cluster 6 &#8211; Sliver C2 over mTLS\\n\\n  * mtls[:\/\/]23.27.143[.]170:443\\n\\n\\n\\n### Cluster 6 &#8211; Sliver C2 IP\\n\\n  * 23.27.143[.]170\\n\\n\\n\\n### Cluster 7 &#8211; XMRig downloader script\\n\\n  * 0ed72d52347bfe4a78afff8a6982a64050c8fc86d8957a20eeb3e0f3f5342ed0\\n\\n\\n\\n### Cluster 7 &#8211; XMRig sample\\n\\n  * 96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46\\n\\n\\n\\n### Cluster 7 &#8211; XMRig configuration\\n\\n  * 7aa88a64a527ade7d93c20faf23b54f2ee33ad9b1246cdc2f8ded2ab639affb1\\n\\n\\n\\n### Cluster 7 &#8211; XMRig remote location IP\\n\\n  * 83[.]229[.]126[.]195\\n\\n\\n\\n### Cluster 7 &#8211; XMRig remote URL\\n\\n  * hxxp:\/\/83[.]229[.]126[.]195:8081\/xmrig\\n\\n\\n\\n### Cluster 7 &#8211; XMRig configuration file remote location\\n\\n  * hxxp:\/\/83[.]229[.]126[.]195:8081\/config[.]json\\n\\n\\n\\n### Cluster 8 &#8211; Nim-based backdoor\\n\\n  * 0c87871642f84e09e8d3fb23ec36bf55601323e31151a7017a85dbec929cf15d\\n\\n\\n\\n### Cluster 8 &#8211; Download URL for the Nim-based backdoor\\n\\n  * hxxps:\/\/1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p[.]worf[.]replit.dev\/download\\n\\n\\n\\n### Cluster 8 &#8211; Attacker controlled sub-domain hosting the Nim-based backdoor\\n\\n  * a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p[.]worf[.]replit.dev\\n\\n\\n\\n### Cluster 8 &#8211; Attacker IP that downloaded the Nim-based backdoor\\n\\n  * 79[.]135[.]105[.]208\\n\\n\\n\\n### Cluster 8 &#8211; C2 for Nim-based backdoor\\n\\n  * hxxp:\/\/13[.]62[.]52[.]206:5004\\n\\n\\n\\n### Cluster 8 &#8211; C2 IP for Nim-based backdoor\\n\\n  * 13[.]62[.]52[.]206\\n\\n\\n\\n### Cluster 8 &#8211; KScan &#8211; scanning tool\\n\\n  * 18d77c9c5bbb5b9d5bdfd366fdfcf26bad9e64c63ca865fad711bcce8e3d5a80\\n\\n\\n\\n### Cluster 8 &#8211; IP related to Nim-based backdoor and KScan\\n\\n  * 176[.]65[.]139[.]31\\n\\n\\n\\n### Cluster 9 &#8211; gsocket\\n\\n  * d94f75a70b5cabaf786ac57177ed841732e62bdcc9a29e06e5b41d9be567bcfa\\n\\n\\n\\n### Cluster 9 &#8211; gsocket secret file\\n\\n  * 5bc5998161056b7c8f70c9724d8a63abc7ff8c3843b91c30cffab0899e39b7f8\\n\\n\\n\\n### Cluster 9 &#8211; IP related to Miner activity\\n\\n  * 47[.]104[.]248[.]7\\n\\n\\n\\n### Cluster 10 &#8211; VManage credential extractor script\\n\\n  * b0f51b098842cd630097b462aab0ec357e2c7824af37cca6d08165265da2c2d3\\n\\n\\n\\n### Cluster 10 &#8211; Check for root escalation\\n\\n  * 72f570ce97de3eaaffef33d90b0c337a153fc9690cc34ee207b557d868360060\\n  * 17302d903baf182f94dc3be40ab1e0874dd0eb2ec5255bf9131fd53591efe925&#8243;,&#8221;published&#8221;:&#8221;2026-05-14T16:02:36&#8243;,&#8221;modified&#8221;:&#8221;2026-05-14T16:02:36&#8243;,&#8221;type&#8221;:&#8221;talosblog&#8221;,&#8221;title&#8221;:&#8221;Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-20122&#8243;,&#8221;CVE-2026-20127&#8243;,&#8221;CVE-2026-20128&#8243;,&#8221;CVE-2026-20133&#8243;,&#8221;CVE-2026-20182&#8243;],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:10,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/blog.talosintelligence.com\/sd-wan-ongoing-exploitation\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-14T18:05:08&#8243;,&#8221;description&#8221;:&#8221;* Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[9,6,8,36,12,13,7,69,11,5],"class_list":["post-54597","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-critical","tag-cve","tag-cvss","tag-cvss-100","tag-exploit","tag-news","tag-security","tag-talosblog","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=54597\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-05-14T18:05:08&#8243;,&#8221;description&#8221;:&#8221;* Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=54597\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-14T13:52:35+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20\",\"datePublished\":\"2026-05-14T13:52:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597\"},\"wordCount\":3073,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-10.0\",\"exploit\",\"news\",\"Security\",\"talosblog\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=54597#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597\",\"name\":\"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-14T13:52:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=54597\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=54597#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=54597","og_locale":"en_US","og_type":"article","og_title":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-05-14T18:05:08&#8243;,&#8221;description&#8221;:&#8221;* Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst...","og_url":"https:\/\/zero.redgem.net\/?p=54597","og_site_name":"zero redgem","article_published_time":"2026-05-14T13:52:35+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=54597#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=54597"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20","datePublished":"2026-05-14T13:52:35+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=54597"},"wordCount":3073,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-10.0","exploit","news","Security","talosblog","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=54597#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=54597","url":"https:\/\/zero.redgem.net\/?p=54597","name":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-14T13:52:35+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=54597#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=54597"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=54597#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities_TALOSBLOG:51F5173F108B01EE2E227083EBCF7F20"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/54597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=54597"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/54597\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=54597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=54597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=54597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}