View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Dirty Frag Linux kernel LPE chain circulating with public exploit

🚨 ACTIVE EXPLOITS & INCIDENTS

  • CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation (Tenable) A critical CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller/Manager is actively exploited by a sophisticated actor (UAT-8616) since 2023, with 10+ other clusters leveraging public PoCs post-disclosure (May 14). Immediate patching is mandated by CISA; unpatched systems are fully compromised.
  • Mini Shai-Hulud: Self-Propagating Supply Chain Worm Hits npm & PyPI (Tenable) TeamPCP’s worm compromised 170+ npm/PyPI packages, including those with valid SLSA Level 3 provenance, stealing developer and cloud credentials. Systems with these packages must be treated as fully compromised. This is a new class of supply chain attack defeating build integrity controls—urgent audit and remediation required.

🔓 VULNERABILITIES & CVEs

📋 VENDOR BULLETINS & LAW ENFORCEMENT

🕵️ THREAT RESEARCH & DEEP DIVES

📰 LESSER-KNOWN / UNDER-REPORTED

  • No significant under-reported items this cycle.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check