Cisco SD-WAN Zero-Day Exploited Months Before Patching

2026-06-25T07:24:03Z89c4472d5a6f4eb1abd287837aa35d0aed2dc95b97136723aab0d4a5874e463d
AI supply chainAIVEXAmadeyC2 takedownCI/CDCVE-2026-20245CiscoMistic RATSD-WANStealCUbiquitiendpoint securityexploitationmacOSpatching delayransomwaresupply chaintriage modelzero-day

What happened

The feed highlights a widely exploited Cisco SD‑WAN zero‑day (CVE-2026-20245) that was abused for months before disclosure and patching, indicating active in-the-wild exploitation and delayed remediation. Other notable stories include a coordinated disruption of hundreds of Amadey/StealC C2 servers, critical Ubiquiti flaws enabling remote unauthenticated changes, macOS attack chains that can silently disable endpoint security from a non-admin account, the emergence of the Mistic RAT used by initial access brokers feeding multiple ransomware families, exploitable CI/CD weaknesses that threaten

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
89c4472d5a6f4eb1abd287837aa35d0aed2dc95b97136723aab0d4a5874e463d
Enrichment time
2026-06-25T07:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco SD-WAN Zero-Day Exploited Months Before Patching · Baitaphish