Cisco warns of unpatched SD-WAN zero-day exploited in attacks
2026-06-05T07:23:30Z•b3c0cdae5d885a2885c91389979147cbca1b1a2164a58a8fb0465dc9f004b1a2
ATG systems','critical infrastructure','Atlas RAT','Chinese APT/CISACVE-2026-20245CiscoDentaQuestDoSHTTP/2 BombHola BrowserIronWormMagecartSD-WANStripe abuseUnified CMWFPcredential theftcryptominerdata breachexploitfuel tank monitoringnpmproof-of-conceptroot escalationsupply-chainunpatchedzero-day
What happened
Multiple high-impact security incidents reported: Cisco disclosed an actively exploited, unpatched SD‑WAN zero‑day (CVE-2026-20245) that enables local root privilege escalation; Cisco also warned of a separate critical Unified Communications Manager flaw with PoC exploit code. Other notable incidents include supply‑chain compromises (Hola Browser Windows build delivering a cryptominer; IronWorm infecting 36 npm packages), a Magecart campaign abusing Stripe to host stolen card data, large data breaches (DentaQuest ~2.6M accounts; WFP self‑registration breach affecting ~600k Gaza households), a新
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b3c0cdae5d885a2885c91389979147cbca1b1a2164a58a8fb0465dc9f004b1a2
- Enrichment time
- 2026-06-05T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.