Cisco SD-WAN Zero-Day Exploited Months Before Patching
2026-06-25T07:24:03Z•89c4472d5a6f4eb1abd287837aa35d0aed2dc95b97136723aab0d4a5874e463d
AI supply chainAIVEXAmadeyC2 takedownCI/CDCVE-2026-20245CiscoMistic RATSD-WANStealCUbiquitiendpoint securityexploitationmacOSpatching delayransomwaresupply chaintriage modelzero-day
What happened
The feed highlights a widely exploited Cisco SD‑WAN zero‑day (CVE-2026-20245) that was abused for months before disclosure and patching, indicating active in-the-wild exploitation and delayed remediation. Other notable stories include a coordinated disruption of hundreds of Amadey/StealC C2 servers, critical Ubiquiti flaws enabling remote unauthenticated changes, macOS attack chains that can silently disable endpoint security from a non-admin account, the emergence of the Mistic RAT used by initial access brokers feeding multiple ransomware families, exploitable CI/CD weaknesses that threaten
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 89c4472d5a6f4eb1abd287837aa35d0aed2dc95b97136723aab0d4a5874e463d
- Enrichment time
- 2026-06-25T07:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.