Cisco warns of unpatched SD-WAN zero-day exploited in attacks
2026-06-05T13:23:29Z•d883f83c316f968e78bbfda187615d35478f022e46f07971a0a2cd3edbb49ddc
ATGAtlas RATCVE-2026-20245CiscoDentaQuestDoSHTTP/2 BombHola BrowserIronWormMagecartPoCSD-WANStripeUnified CMWFPcryptominerdata breachexploitfuel-systemsmalwarenpmroot escalationsanctionssupply-chainzero-day
What happened
Multiple high-impact security stories: Cisco disclosed an actively exploited, unpatched SD‑WAN zero‑day (CVE‑2026‑20245) in Catalyst SD‑WAN Manager enabling root privilege escalation; Cisco also warned of a separate critical Unified Communications Manager flaw with public PoC. Other notable incidents include supply‑chain compromises (Hola Browser delivering a cryptominer, 36 npm packages infected by IronWorm), a Magecart campaign abusing Stripe to host skimmers/exfiltrated cards, large data breaches (DentaQuest, WFP Palestine registration), a new HTTP/2 “Bomb” DoS that can crash servers from a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d883f83c316f968e78bbfda187615d35478f022e46f07971a0a2cd3edbb49ddc
- Enrichment time
- 2026-06-05T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.