INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Critical Cisco SD-WAN Bug Exploited in Zero-Day Attacks

| 2026-05-14 16:02 CRITICAL HIGH
Executive Summary AI-generated
The recent discovery of CVE-2026-20182 in Cisco's SD-WAN systems has sent shockwaves through the cybersecurity community, particularly among nation-state actors. This critical vulnerability allows hackers to exploit an authentication bypass bug that had been previously patched by Rapid7, a leading security firm. The fact that this issue was not discovered until May 14th and had already been exploited overnight raises concerns about the speed at which vulnerabilities can be pushed into production environments. As a result, CISA has issued an emergency directive for all federal agencies to patch the exploit as soon as possible, emphasizing the importance of timely action in preventing potential attacks.
Technical Mitigations AI-generated
* Implement a secure patching process: Ensure that all affected Cisco SD-WAN systems receive the latest security patches as soon as possible, ideally within the specified deadline of Sunday. * Monitor network logs and perform regular vulnerability scans: Regularly review network logs to detect any suspicious activity or potential vulnerabilities. Perform thorough vulnerability scanning on all affected systems to identify and remediate any weaknesses. * Implement additional security controls: Consider implementing additional security controls such as multi-factor authentication, intrusion detection and prevention systems (IDPS), and secure access control mechanisms to further protect against unauthorized access. * Conduct a thorough risk assessment and implement mitigation strategies: Conduct a comprehensive risk assessment of the affected network and implement mitigation strategies such as encryption, firewalls, and secure communication protocols to minimize the impact of any potential security breaches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt Strike CVE-2022-20775CVE-2022-20775 CVE-2026-20122CVE-2026-20122 CVE-2026-20182CVE-2026-20182 CVE-2026-20128CVE-2026-20128 CVE-2026-20127CVE-2026-20127 CVE-2026-20133CVE-2026-20133
Target & Sectors
NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES technologytechnology
Incident Timeline
‎February 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎February 2026
Threat actors exploited a Cisco SD-WAN bug in the wild.
‎March 3, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎at least March 3, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild, targeting Cluster 4.
vulnerability CVE-2026-20133
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
general_metric 4 Cluster
‎March 4, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎at least March 4, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild, targeting Cluster 3.
vulnerability CVE-2026-20133
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
general_metric 3 Cluster
‎March 5, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎at least March 5, 2026
Threat actors exploited a Cisco SD-WAN bug to gain access through an open SSH service on port 22.
malware Sliver
observable fece5b954e69b2c6a8d0a1029631a0d7
organisation CWan
general_metric 31337 port
general_metric 22 port
infrastructure 6 server Cluster
‎March 6, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild.
‎at least March 6, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild, targeting at least one cluster since March 6, 2026.
vulnerability CVE-2026-20133
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
general_metric 1 Cluster
‎March 10, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎at least March 10, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild, targeting at least two clusters that had been actively exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since March 10, 2026.
vulnerability CVE-2026-20133
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
general_metric 2 Cluster
‎as early as March 10, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in Cluster 8.
general_metric 8 Attacker
‎March 13, 2026
Threat actors exploited a publicly available red team framework to deploy malware on Cisco SD-WAN Cluster 5.
general_metric 5 AdaptixC2
‎Mar 13, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎March 2026
Threat actors exploited a previously disclosed vulnerability, CVE-2026-20133.
vulnerability CVE-2026-20133
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
‎March 17, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild.
‎at least March 17, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug in the wild by deploying an XMRig miner and a peer-based proxying and tunneling tool.
general_metric 9 gsocket
‎March 25, 2026
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild.
‎at least March 25, 2026
Threat actors exploited a Cisco SD-WAN bug in the wild by downloading and deploying an XMRig sample via a shell script from "83.229.126[.]195".
general_metric 7 XMRig
‎March 28, 2026
Threat actors exploited a Maximum Severity Cisco SD-WAN bug on the "194[.]163[.]175[.]135" IP address, using it as a Mythic C2 server to target another compromised system.
malware Sliver
observable fece5b954e69b2c6a8d0a1029631a0d7
organisation CWan
general_metric 31337 port
general_metric 22 port
infrastructure 6 server Cluster
‎2026/05/14
Threat actors exploited a Maximum Severity Cisco SD-WAN bug by using the peering authentication mechanism.
‎March to April 2026
Threat actors exploited the unpatched Cisco SD-WAN systems from March to April 2026.
‎2026/02/10T22:51:36+
Threat actors exploited a Maximum Severity Cisco SD-WAN bug by using the "Accepted publickey for vmanage-admin" authentication mechanism to gain unauthorized access through an SSH connection.
observable auth.log
‎2026/05/15
Threat actors exploited a maximum severity Cisco SD-WAN bug in the wild, targeting CVE-2026-20182.
organisation SD-WAN vSmart
organisation SD-WAN vManage
organisation ITW
organisation Security Advisory
organisation CVSS
organisation Breaks a Pen Test Organizations
organisation Catalyst SD-WAN Controller
organisation Cisco Catalyst SD-WAN
organisation Cisco Catalyst SD-WAN Controller
organisation SD-WAN Cloud
organisation Cisco CVE-2026-20182
infrastructure 1.1.1
infrastructure 192.168.3
organisation SD-WAN
organisation CVE-2026
organisation DTLS
organisation SSH
infrastructure 7 IP Cluster
infrastructure 8 based Download URL
infrastructure 00 download
organisation the Common Vulnerability Scoring System
financial 1 Cluster
financial 10 Cluster
organisation Cisco Security Advisory
organisation CVE-202128
organisation ClamAV
financial 66469 Snort SIDs
financial 66462 Snort SIDs
organisation CVE
organisation UAT-8616
organisation Cisco SD-WAN
organisation UDP
organisation JWT
organisation API
organisation Token
organisation JSP
organisation XenShell
organisation NETCONF
organisation ORB
organisation TAC
organisation the Recommendations and Detection Guidance
organisation JavaServer Pages
organisation IPs
organisation AES
organisation IP
organisation TCP
organisation VPS
organisation Nim
organisation RSA
organisation Nimplant
organisation the Global Socket Relay Network
organisation GSRN
financial 2 Cluster
financial 3 Cluster
financial 4 Cluster
data_breach 16 byte
organisation CVE-2022
organisation the Catalyst Controller
infrastructure Linux
organisation Maximum Severity Cisco SD-WAN Bug Exploited
organisation McKee
organisation Cisco Talos
organisation Catalyst
organisation Controller
organisation vHub
organisation Critical Infrastructure
organisation CI
organisation KEY
organisation the Cisco Catalyst SD-WAN
organisation UI
organisation SD-WAN Controller
‎May 2026
Threat actors exploited a vulnerability in Cisco's SD-WAN software.
‎May 17, 2026
Threat actors exploited the Maximum Severity Cisco SD-WAN Bug CVE-2026-20182 in the wild.
vulnerability CVE-2026-20182
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
financial
1
Cluster
Metrics
financial
10
Cluster
Metrics
infrastructure
6
Server Cluster
Metrics
financial
66,469
Snort Sids
Metrics
financial
66,462
Snort Sids
Metrics
infrastructure
7
Ip Cluster
Metrics
infrastructure
8
Based Download Url
Metrics
infrastructure
0
Download
Metrics
financial
2
Cluster
Metrics
financial
3
Cluster
Metrics
financial
4
Cluster
Metrics
data_breach
16
Byte
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎1.1.1
Software Version
Metrics
infrastructure
‎192.168.3
Software Version