Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Posted on March 8, 2026 By CWS

Recent reports indicate a significant rise in the exploitation of a Cisco Catalyst SD-WAN vulnerability. Initially targeted as a zero-day, this security loophole has become a frequent target for cybercriminals, according to exposure management firm WatchTowr.

Escalating Threat Activity

WatchTowr has identified four vulnerabilities within the Cisco Catalyst SD-WAN, including CVE-2026-20127, which has been actively exploited alongside an older flaw, CVE-2022-20775. This combination is utilized to bypass security measures, escalate user privileges, and maintain unauthorized access to systems.

Cisco’s security division, Talos, has tracked these exploits back to a sophisticated threat group known as UAT-8616. Although the group’s origins and motives remain unclear, their activities have been ongoing since at least 2023.

Global Exploitation Patterns

Ryan Dewhurst, head of proactive threat intelligence at WatchTowr, shared with SecurityWeek that the exploitation of CVE-2026-20127 is now widespread. He noted, “This has evolved from a targeted operation to a global phenomenon.” The increase in attack attempts was particularly pronounced on March 4, with numerous IP addresses involved and notable activity recorded in the United States.

Dewhurst warned of continued threats, stating, “As exploitation becomes more widespread, any exposed system should be assumed compromised unless verified otherwise.”

Ongoing Security Challenges

Cisco has updated its advisory from February 25 to include information on two additional SD-WAN vulnerabilities: CVE-2026-20128 and CVE-2026-20122. Both can be exploited by authenticated users to gain elevated privileges. While details of these attacks are scarce, they appear to involve multiple chained vulnerabilities.

There is uncertainty about whether the same threat actors are responsible for all current campaigns targeting SD-WAN vulnerabilities. Cisco recently flagged a zero-day vulnerability in its Secure Email Gateway appliances, attributed to China-linked hackers, though it’s unclear if these incidents are connected.

The continued discovery and exploitation of such vulnerabilities underscore the importance of robust cybersecurity measures. Organizations using Cisco products are advised to implement the latest security patches and monitor their systems closely.

Security Week News Tags:Authentication, Cisco, Cybersecurity, Exploitation, privilege escalation, SD-WAN, Threat Actors, Vulnerability, Webshells, zero-day

Post navigation

Previous Post: Critical Flaw in AVideo Platform Enables Stream Takeover
Next Post: High-Value Windows RDS Exploit Surfaces on Dark Web

Related Posts

High-Severity Remote Code Execution Vulnerability Patched in OpenSSL High-Severity Remote Code Execution Vulnerability Patched in OpenSSL Security Week News
Microsoft Offers Free Windows 10 Extended Security Update Options as EOS Nears Microsoft Offers Free Windows 10 Extended Security Update Options as EOS Nears Security Week News
Soverli Raises .6 Million for Secure Smartphone OS Soverli Raises $2.6 Million for Secure Smartphone OS Security Week News
Iran-Linked Cyberattacks Disrupt US Infrastructure Iran-Linked Cyberattacks Disrupt US Infrastructure Security Week News
Chrome 140 Update Patches Sixth Zero-Day of 2025 Chrome 140 Update Patches Sixth Zero-Day of 2025 Security Week News
FBI Alert on Security Risks from Chinese Mobile Apps FBI Alert on Security Risks from Chinese Mobile Apps Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyber Insurance Enhances CISO Budget Negotiations
  • LofyGang Returns with Minecraft Malware Campaign
  • BlobPhish Exploits Microsoft 365 with New Tactics
  • Vimeo Data Breach Exposes User Details via Third-Party Vendor
  • Remote Desktop Warning Issues in Windows 11 Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyber Insurance Enhances CISO Budget Negotiations
  • LofyGang Returns with Minecraft Malware Campaign
  • BlobPhish Exploits Microsoft 365 with New Tactics
  • Vimeo Data Breach Exposes User Details via Third-Party Vendor
  • Remote Desktop Warning Issues in Windows 11 Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark