Cisco warns of unpatched SD-WAN zero-day exploited in attacks

2026-06-05T07:23:30Zb3c0cdae5d885a2885c91389979147cbca1b1a2164a58a8fb0465dc9f004b1a2
ATG systems','critical infrastructure','Atlas RAT','Chinese APT/CISACVE-2026-20245CiscoDentaQuestDoSHTTP/2 BombHola BrowserIronWormMagecartSD-WANStripe abuseUnified CMWFPcredential theftcryptominerdata breachexploitfuel tank monitoringnpmproof-of-conceptroot escalationsupply-chainunpatchedzero-day

What happened

Multiple high-impact security incidents reported: Cisco disclosed an actively exploited, unpatched SD‑WAN zero‑day (CVE-2026-20245) that enables local root privilege escalation; Cisco also warned of a separate critical Unified Communications Manager flaw with PoC exploit code. Other notable incidents include supply‑chain compromises (Hola Browser Windows build delivering a cryptominer; IronWorm infecting 36 npm packages), a Magecart campaign abusing Stripe to host stolen card data, large data breaches (DentaQuest ~2.6M accounts; WFP self‑registration breach affecting ~600k Gaza households), a新

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b3c0cdae5d885a2885c91389979147cbca1b1a2164a58a8fb0465dc9f004b1a2
Enrichment time
2026-06-05T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.