Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Cisco SD-WAN Vulnerability Exploitation Grows Rapidly

Posted on March 8, 2026 By CWS

Recent reports indicate a significant rise in the exploitation of a Cisco Catalyst SD-WAN vulnerability. Initially targeted as a zero-day, this security loophole has become a frequent target for cybercriminals, according to exposure management firm WatchTowr.

Escalating Threat Activity

WatchTowr has identified four vulnerabilities within the Cisco Catalyst SD-WAN, including CVE-2026-20127, which has been actively exploited alongside an older flaw, CVE-2022-20775. This combination is utilized to bypass security measures, escalate user privileges, and maintain unauthorized access to systems.

Cisco’s security division, Talos, has tracked these exploits back to a sophisticated threat group known as UAT-8616. Although the group’s origins and motives remain unclear, their activities have been ongoing since at least 2023.

Global Exploitation Patterns

Ryan Dewhurst, head of proactive threat intelligence at WatchTowr, shared with SecurityWeek that the exploitation of CVE-2026-20127 is now widespread. He noted, “This has evolved from a targeted operation to a global phenomenon.” The increase in attack attempts was particularly pronounced on March 4, with numerous IP addresses involved and notable activity recorded in the United States.

Dewhurst warned of continued threats, stating, “As exploitation becomes more widespread, any exposed system should be assumed compromised unless verified otherwise.”

Ongoing Security Challenges

Cisco has updated its advisory from February 25 to include information on two additional SD-WAN vulnerabilities: CVE-2026-20128 and CVE-2026-20122. Both can be exploited by authenticated users to gain elevated privileges. While details of these attacks are scarce, they appear to involve multiple chained vulnerabilities.

There is uncertainty about whether the same threat actors are responsible for all current campaigns targeting SD-WAN vulnerabilities. Cisco recently flagged a zero-day vulnerability in its Secure Email Gateway appliances, attributed to China-linked hackers, though it’s unclear if these incidents are connected.

The continued discovery and exploitation of such vulnerabilities underscore the importance of robust cybersecurity measures. Organizations using Cisco products are advised to implement the latest security patches and monitor their systems closely.

Security Week News Tags:Authentication, Cisco, Cybersecurity, Exploitation, privilege escalation, SD-WAN, Threat Actors, Vulnerability, Webshells, zero-day

Post navigation

Previous Post: Critical Flaw in AVideo Platform Enables Stream Takeover
Next Post: High-Value Windows RDS Exploit Surfaces on Dark Web

Related Posts

Hacker Conversations: Katie Paxton-Fear Talks Autism, Morality and Hacking Hacker Conversations: Katie Paxton-Fear Talks Autism, Morality and Hacking Security Week News
Rethinking Success in Security: Why Climbing the Corporate Ladder Isn’t Always the Goal Rethinking Success in Security: Why Climbing the Corporate Ladder Isn’t Always the Goal Security Week News
TeamFiltration Abused in Entra ID Account Takeover Campaign TeamFiltration Abused in Entra ID Account Takeover Campaign Security Week News
With Retail Cyberattacks on the Rise, Customers Find Orders Blocked and Shelves Empty With Retail Cyberattacks on the Rise, Customers Find Orders Blocked and Shelves Empty Security Week News
Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Security Week News
Interpol Targets Infostealers: 20,000 IPs Taken Down, 32 Arrested, 216,000 Victims Notified Interpol Targets Infostealers: 20,000 IPs Taken Down, 32 Arrested, 216,000 Victims Notified Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • BlackSanta Malware Disables Security Before Attack
  • Microsoft Fixes 84 Security Flaws, Including Two Zero-Days
  • UNC6426 Leverages npm Flaw for Rapid AWS Admin Access
  • Critical Microsoft .NET Vulnerability Demands Immediate Attention
  • Siemens and Schneider Lead ICS Patch Tuesday Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • BlackSanta Malware Disables Security Before Attack
  • Microsoft Fixes 84 Security Flaws, Including Two Zero-Days
  • UNC6426 Leverages npm Flaw for Rapid AWS Admin Access
  • Critical Microsoft .NET Vulnerability Demands Immediate Attention
  • Siemens and Schneider Lead ICS Patch Tuesday Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News