Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Posted on March 8, 2026 By CWS

Recent reports indicate a significant rise in the exploitation of a Cisco Catalyst SD-WAN vulnerability. Initially targeted as a zero-day, this security loophole has become a frequent target for cybercriminals, according to exposure management firm WatchTowr.

Escalating Threat Activity

WatchTowr has identified four vulnerabilities within the Cisco Catalyst SD-WAN, including CVE-2026-20127, which has been actively exploited alongside an older flaw, CVE-2022-20775. This combination is utilized to bypass security measures, escalate user privileges, and maintain unauthorized access to systems.

Cisco’s security division, Talos, has tracked these exploits back to a sophisticated threat group known as UAT-8616. Although the group’s origins and motives remain unclear, their activities have been ongoing since at least 2023.

Global Exploitation Patterns

Ryan Dewhurst, head of proactive threat intelligence at WatchTowr, shared with SecurityWeek that the exploitation of CVE-2026-20127 is now widespread. He noted, “This has evolved from a targeted operation to a global phenomenon.” The increase in attack attempts was particularly pronounced on March 4, with numerous IP addresses involved and notable activity recorded in the United States.

Dewhurst warned of continued threats, stating, “As exploitation becomes more widespread, any exposed system should be assumed compromised unless verified otherwise.”

Ongoing Security Challenges

Cisco has updated its advisory from February 25 to include information on two additional SD-WAN vulnerabilities: CVE-2026-20128 and CVE-2026-20122. Both can be exploited by authenticated users to gain elevated privileges. While details of these attacks are scarce, they appear to involve multiple chained vulnerabilities.

There is uncertainty about whether the same threat actors are responsible for all current campaigns targeting SD-WAN vulnerabilities. Cisco recently flagged a zero-day vulnerability in its Secure Email Gateway appliances, attributed to China-linked hackers, though it’s unclear if these incidents are connected.

The continued discovery and exploitation of such vulnerabilities underscore the importance of robust cybersecurity measures. Organizations using Cisco products are advised to implement the latest security patches and monitor their systems closely.

Security Week News Tags:Authentication, Cisco, Cybersecurity, Exploitation, privilege escalation, SD-WAN, Threat Actors, Vulnerability, Webshells, zero-day

Post navigation

Previous Post: Critical Flaw in AVideo Platform Enables Stream Takeover
Next Post: High-Value Windows RDS Exploit Surfaces on Dark Web

Related Posts

Recent 7-Zip Vulnerability Exploited in Attacks Recent 7-Zip Vulnerability Exploited in Attacks Security Week News
Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency Security Week News
ThreatSpike Raises  Million in Series A Funding ThreatSpike Raises $14 Million in Series A Funding Security Week News
Zscaler Acquires AI Security Company SPLX Zscaler Acquires AI Security Company SPLX Security Week News
40,000 Servers at Risk Due to cPanel Exploit 40,000 Servers at Risk Due to cPanel Exploit Security Week News
Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Cisco, Chrome, Arista Security Flaws
  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Cisco, Chrome, Arista Security Flaws
  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark