Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast

2026-06-07T08:51:43Zea87ea51a005d1291b0668f6cb5fb3d15e732ca377e7f1eb39fb5420a954fd9d
0-dayAI misuseAgent Memory GuardAgentGGAnthropicCVE-2026-20127CVE-2026-20182CVE-2026-20245CiscoCisco SD-WANDashlaneLet’s EncryptMerkle Tree CertificatesPatch Tuesdaybrute-forceencrypted vaultsexploitationkeyless car relay attackpassword managerpost-quantum

What happened

Week-in-review covering multiple security developments: a Cisco Catalyst SD-WAN 0-day (CVE-2026-20245) is being actively exploited with no vendor patch available; exploitation requires netadmin credentials or prior compromise (CVE-2026-20182/CVE-2026-20127). Dashlane disclosed a brute-force attack that allowed an actor to copy encrypted user vaults (no evidence of internal system compromise). Let’s Encrypt announced work on post-quantum Merkle Tree Certificates (MTCs) targeted for staging in late 2026. Anthropic released analysis showing AI is enabling lower-skill actors to carry out advanced攻

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
ea87ea51a005d1291b0668f6cb5fb3d15e732ca377e7f1eb39fb5420a954fd9d
Enrichment time
2026-06-07T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.