Cisco zero-day under ongoing attack by persistent threat group
2026-05-15T14:51:41Z•376d3503c63ccd6366c4403ed119f8895f2abb28249863489fdc33ab14e816c2
active-exploitationciscofirewallincident-responsenetwork-securitypatchingpersistent-threat-groupsd-wanvulnerability-disclosurezero-day
What happened
A Cisco SD‑WAN zero‑day is being actively exploited by a persistent threat group that is also tied to recently disclosed vulnerabilities affecting Cisco firewalls and SD‑WAN systems. The campaign represents ongoing targeted attacks against Cisco networking gear; affected organizations should assume active exploitation, prioritize vendor mitigations and patches, and increase monitoring of edge and VPN/SD‑WAN infrastructure for indicators of compromise.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 376d3503c63ccd6366c4403ed119f8895f2abb28249863489fdc33ab14e816c2
- Enrichment time
- 2026-05-15T14:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.