Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks

2026-06-16T07:24:04Z8d2ac83456eb3dc6f524920920ca8bd6c6919cdd0a906555a78c5b79befd9317
Chinese cyberespionageCiscoContiCouncil of EuropeFBIGoogleMaineMisereNewCoreNovo NordiskOutsider EnterpriseSD‑WANShinyHuntersTchapThe GentlemenUNC6508arbitrary file writecve-2026-20262data breachfake submissionsphishingransomwarestartup fundingzero-day

What happened

A batch of major cyber incidents and developments: Cisco patched an actively exploited Catalyst SD‑WAN zero‑day (CVE-2026-20262) allowing arbitrary file writes; Mackay Sugar was hit by ransomware blamed on The Gentlemen, disrupting mills; Google TAG tracked Chinese cyberespionage group UNC6508 targeting medical, military and AI research in North America. Other notable items: Novo Nordisk reported an IT systems breach exposing personal data; French Tchap government messaging platform was breached by an actor calling itself ‘Misere’ (≈73,000 accounts affected); ShinyHunters claims a 297 GB leak/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
8d2ac83456eb3dc6f524920920ca8bd6c6919cdd0a906555a78c5b79befd9317
Enrichment time
2026-06-16T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks · Baitaphish