Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited

2026-03-08T13:24:15Z3feccf67fa775cda5480391e07bf9fc13fcc9476b1944d112d7887890ed16f78
BoryptGrabCISACVE-2026-20127Cisco CatalystCoruna exploit kitFBIGitHubICSKEVPentagon CISORockwellSD-WANUS cyber strategyWatchTowrexploitationiOSin-the-wild exploitationstealersurveillance

What happened

SecurityWeek reports multiple active and emerging threats: CVE-2026-20127 (Cisco Catalyst SD‑WAN) is now being widely exploited from numerous unique IPs; CISA added 23 iOS vulnerabilities used by the nation‑state-grade Coruna exploit kit to its KEV list; over 100 GitHub repositories are distributing the BoryptGrab stealer (targets browser and crypto wallet data); a Rockwell ICS vulnerability disclosed in 2021 is being exploited in the wild; and the FBI is investigating suspicious activity on a system holding sensitive surveillance information. Coverage also includes U.S. cyber strategy updates

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
3feccf67fa775cda5480391e07bf9fc13fcc9476b1944d112d7887890ed16f78
Enrichment time
2026-03-08T13:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited · Baitaphish