View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Cisco Catalyst SD-WAN CVSS 10 auth bypass under active exploitation

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Lawmakers Demand Answers as CISA Tries to Contain Data Leak Krebs on Security A CISA contractor accidentally published AWS GovCloud keys and sensitive agency secrets publicly on GitHub, triggering an ongoing breach containment effort. Lawmakers are pressing CISA for accountability as leaked credentials remain a critical risk. Why it matters: Immediate credential revocation and audit of cloud access are essential to prevent further compromise of government infrastructure.
  • Microsoft Defender Zero-Days Exploited in the Wild Sentinel One Blog Two zero-day vulnerabilities in Microsoft Defender were actively exploited against targeted victims, highlighting ongoing attacker focus on endpoint security bypass. Details remain limited but detection and mitigation guidance is available. Why it matters: Organizations must prioritize deploying latest Defender updates and monitor for indicators of compromise related to these zero-days.

🔓 VULNERABILITIES & CVEs

  • CVE-2026-9082: Highly Critical SQL Injection in Drupal Core Tenable Cyber Exposure A critical unauthenticated SQL injection affects Drupal sites using PostgreSQL, allowing remote code execution via the database abstraction layer. CVSS 9.8. Patches released for all supported branches plus exceptional EOL versions. No active exploitation reported but PoC code is public. Why it matters: Immediate patching is mandatory for Drupal sites on PostgreSQL to prevent potential full site compromise.
  • CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation Tenable Cyber Exposure A CVSS 10.0 authentication bypass zero-day in Cisco Catalyst SD-WAN Controller and Manager is exploited by a sophisticated threat actor (UAT-8616) since 2023, with multiple other threat groups joining post-PoC release. Patches available; CISA mandates immediate remediation. Why it matters: SD-WAN infrastructure is critical network backbone; unpatched devices risk full network compromise and lateral movement.
  • Dirty Frag (CVE-2026-43284 & CVE-2026-43500): Linux Kernel Local Privilege Escalation Tenable Cyber Exposure A chained local privilege escalation in Linux kernel with public exploit code extends the Copy Fail vulnerability class. Affects multiple distros; patches pending but expected imminently. Module blacklist mitigations partially effective. Why it matters: Linux hosts remain at risk of local root escalation; patching or applying mitigations is critical to prevent privilege abuse.
  • Copy Fail (CVE-2026-31431): Widespread Linux Kernel Privilege Escalation Tenable Cyber Exposure A high severity local root exploit present since 2017 affects nearly all major Linux distros. Public exploit code available and reliable. Some distros lag in patching. Why it matters: Urgent patching required for Linux environments, especially servers exposed to untrusted users or containers.
  • Mattermost OAuth Scope Validation Bypass CVE ThreatInt Mattermost versions <=11.6.0 fail to validate OAuth token scopes on callback, allowing authenticated users to escalate privileges. Why it matters: Patch or mitigate to prevent unauthorized access escalation in collaboration platforms.
  • Multiple Devolutions Server vulnerabilities (CVE-2026-7325, CVE-2026-9246, CVE-2026-9249, CVE-2026-9223, CVE-2026-9047, etc.) reported by CVE ThreatInt reveal widespread improper authorization, missing authentication, and privilege escalation flaws allowing attackers to bypass MFA, export sealed entries, or change passwords without verification. Why it matters: Organizations using Devolutions Server should urgently apply patches and review access controls to prevent credential theft and data leakage.

🕵️ THREAT RESEARCH & DEEP DIVES

  • Mini Shai-Hulud: Self-Propagating Worm Compromises 170+ npm & PyPI Packages Tenable Cyber Exposure TeamPCP group deployed a worm that bypassed SLSA Build Level 3 provenance, stealing developer and cloud credentials from compromised packages including those used by OpenAI and Mistral AI. Any system installing affected packages is fully compromised. Why it matters: Supply chain attacks continue evolving; developers and orgs must audit dependencies, revoke exposed credentials, and tighten package provenance validation.
  • Nimbus Manticore Operations During Iranian Conflict Check Point Research Iranian IRGC-affiliated UNC1549 group conducted destructive attacks on US/Israeli targets, targeting IoT cameras and cloud environments to support kinetic operations and intelligence gathering. Why it matters: Heightened geopolitical tensions translate to increased cyber risk for critical infrastructure and cloud assets in affected sectors.
  • Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Breach Vector Tenable Cyber Exposure Vulnerability exploitation accounts for 31% of breaches; median patch times increased by 11 days. AI accelerates discovery and exploitation speed, emphasizing continuous exposure management and automated remediation. Why it matters: Security teams must prioritize rapid patching and leverage automation to keep pace with evolving attacker capabilities.

📋 VENDOR BULLETINS & LAW ENFORCEMENT

  • Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical, No Zero-Days Exploited Tenable Cyber Exposure Microsoft patched 118 CVEs across Azure, .NET, M365, and Windows components. Notably, no zero-days exploited in the wild this cycle, a positive sign after recent months. Why it matters: Deploy May patches promptly to maintain defense-in-depth and address critical cloud and endpoint vulnerabilities.
  • Oracle April 2026 CPU: 241 CVEs, 34 Critical Tenable Cyber Exposure Oracle’s quarterly update fixed 241 CVEs with 481 patches, including critical fixes for Oracle Communications (139 patches). Why it matters: Oracle customers should prioritize patching critical components to reduce exposure to high-severity flaws.
  • Former US Execs Plead Guilty to Aiding Tech Support Scammers BleepingComputer Two ex-executives of a call-tracking company admitted to concealing a global tech support fraud scheme. Why it matters: Highlights ongoing law enforcement efforts against large-scale fraud and the importance of supply chain and vendor vetting.

📰 LESSER-KNOWN / UNDER-REPORTED

  • CrowdStrike named leader in Gartner’s first Magic Quadrant for Cyberthreat Intelligence Technologies and launched new AI-powered detection tools and integrations. Why it matters: Reflects industry trend toward AI-enhanced threat detection and intelligence fusion, worth monitoring for future defensive capabilities.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check