Cisco Discloses 7th SD-WAN Zero-Day of 2026 — Unpatched Root Escalation,
No Fix in Sight
CVE-2026-20245 is an actively exploited command injection flaw in Cisco Catalyst SD-WAN Manager that escalates to root with no patch and no timeline for one. Discovered by Mandiant during active exploitation. Chains directly after the CVSS 10.0 authentication bypass. Configuration changes pushed to edge devices confirmed. UAT-8616 involved.
Read Full Brief →Threats & Attacks
Command injection in SD-WAN Manager CLI. Root via crafted file upload. No patch, no timeline. Chains after CVSS 10.0 auth bypass. Mandiant found it during active exploitation. Config changes pushed to edge devices confirmed.
NSA and CISA have 60 days to build a classified AI cyber capability benchmark. Voluntary 30-day pre-release testing window. Triggered by Anthropic Mythos autonomous vulnerability exploitation.
Support AJAX endpoint open to unauthenticated users. Nonce in frontend HTML. One request creates admin, exfiltrates passwordless login URL. 2,858 attacks blocked in 24 hours.
Unauthenticated attackers forge GlobalProtect session cookies, bypass MFA, establish VPN sessions. CVSS 9.1. Rapid7 confirmed exploitation across multiple customers. Federal deadline June 19.
Nx Console breach + parallel Megalodon GitHub Actions campaign. TeamPCP open-sourced its framework. Copycat groups active. Full forensic checklist inside.
22,052 incidents. 12,195 confirmed breaches. Ransomware in 44%. Supply chain attacks doubled. Median exploit timeline 5 days. Median patch time 43 days.
Intelligence & Deep Dive
Further Coverage
Four DTLS packets. No credentials. Full admin. Nation-state-linked UAT-8616. CISA Emergency Directive 26-03. The entry point that enables CVE-2026-20245.
Directory traversal in Apex One on-premise server. Discovered during active exploitation. Malicious code auto-deploys to every managed endpoint. CISA KEV. June 4 deadline.
Standard user in, SYSTEM shell out. Public PoC. 6th zero-day in 6 weeks. First 3 confirmed used in real attacks.
VulnCheck confirms real-world attacks. CVSS 9.2. ~34% of all internet web servers exposed. Patch to NGINX 1.30.1 now.
Poisoned Nx Console auto-delivered to 2.2M installs. 3,800 GitHub repos exfiltrated. TeamPCP at SolarWinds scale.
The same TeamPCP campaign that breached GitHub started here. Malicious PyPI packages, credential-stealing worm, IDE persistence hooks.
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise. Trusted by enterprise and government security leaders.
