Cisco zero-day under ongoing attack by persistent threat group

2026-05-15T14:51:41Z376d3503c63ccd6366c4403ed119f8895f2abb28249863489fdc33ab14e816c2
active-exploitationciscofirewallincident-responsenetwork-securitypatchingpersistent-threat-groupsd-wanvulnerability-disclosurezero-day

What happened

A Cisco SD‑WAN zero‑day is being actively exploited by a persistent threat group that is also tied to recently disclosed vulnerabilities affecting Cisco firewalls and SD‑WAN systems. The campaign represents ongoing targeted attacks against Cisco networking gear; affected organizations should assume active exploitation, prioritize vendor mitigations and patches, and increase monitoring of edge and VPN/SD‑WAN infrastructure for indicators of compromise.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
376d3503c63ccd6366c4403ed119f8895f2abb28249863489fdc33ab14e816c2
Enrichment time
2026-05-15T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco zero-day under ongoing attack by persistent threat group · Baitaphish