Cisco warns of unpatched SD-WAN zero-day exploited in attacks

2026-06-05T13:23:29Zd883f83c316f968e78bbfda187615d35478f022e46f07971a0a2cd3edbb49ddc
ATGAtlas RATCVE-2026-20245CiscoDentaQuestDoSHTTP/2 BombHola BrowserIronWormMagecartPoCSD-WANStripeUnified CMWFPcryptominerdata breachexploitfuel-systemsmalwarenpmroot escalationsanctionssupply-chainzero-day

What happened

Multiple high-impact security stories: Cisco disclosed an actively exploited, unpatched SD‑WAN zero‑day (CVE‑2026‑20245) in Catalyst SD‑WAN Manager enabling root privilege escalation; Cisco also warned of a separate critical Unified Communications Manager flaw with public PoC. Other notable incidents include supply‑chain compromises (Hola Browser delivering a cryptominer, 36 npm packages infected by IronWorm), a Magecart campaign abusing Stripe to host skimmers/exfiltrated cards, large data breaches (DentaQuest, WFP Palestine registration), a new HTTP/2 “Bomb” DoS that can crash servers from a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d883f83c316f968e78bbfda187615d35478f022e46f07971a0a2cd3edbb49ddc
Enrichment time
2026-06-05T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.