View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Cisco Catalyst SD-WAN vulnerabilities under active exploitation

Monitoring 63 sources.

🚨 Active Exploits & Incidents

  • Japan's largest taxi operator shuts systems after cyberattack — Nihon Kotsu, Japan's largest taxi operator, shut down part of its infrastructure after a confirmed cyberattack compromised its systems. Details on the attacker or malware used remain scarce but operational impact is significant.
  • Active exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) — Multiple critical authentication bypass flaws in Cisco Catalyst SD-WAN Controller and Manager are actively exploited by sophisticated threat actors including UAT-8616. Patches exist; immediate remediation is mandated by CISA.
  • Dirty Frag Linux kernel privilege escalation (CVE-2026-43284, CVE-2026-43500) — Public exploit code released for this chained local privilege escalation vulnerability in the Linux kernel. Affects multiple distros; patches pending but expected imminently. Exploit extends the "Copy Fail" bug class.
  • Fragnesia Linux kernel privilege escalation (CVE-2026-46300) — New local privilege escalation with public PoC targeting the Linux kernel's XFRM ESP-in-TCP subsystem. Patch released May 13; existing mitigations for Dirty Frag do not cover this. Confirmed working on Ubuntu; no in-the-wild exploitation reported yet.

🔓 Vulnerabilities & CVEs

  • Drupal Core SQL injection (CVE-2026-9082, CVSS 9.8) — Highly critical SQLi in Drupal's database abstraction layer affecting PostgreSQL sites. Unauthenticated remote exploitation possible. Detection PoC and patch diff publicly available; patches released across six supported branches.
  • Lorex 2K Indoor Wi-Fi Camera remote code execution (CVE-2026-15680) — Format string RCE vulnerability exploitable by network-adjacent attackers. Immediate patching recommended.
  • AnyDesk denial-of-service vulnerability (CVE-2026-15681) — Local attackers can cause DoS conditions on AnyDesk installations via screen recording link.
  • 9Router unauthenticated API key exposure (CVE-2026-62327) — Remote attackers can retrieve plaintext API keys for connected AI provider accounts via unprotected API endpoints.
  • 9Router unauthenticated information disclosure (CVE-2026-62328) — Remote access to sensitive user data via unprotected API usage endpoints.
  • Multiple OpenClaw vulnerabilities (CVE-2026-62194 through CVE-2026-62200) — Authentication bypass, privilege escalation, and authorization bypass in versions prior to 2026.6.9. These allow lower-trust callers to execute owner-only tools and bypass network policies. Immediate upgrades advised.

🕵️ Threat Research & Deep Dives

  • Jscrambler npm package backdoored with infostealer malware — Malicious version of the Jscrambler npm package downloaded ~1,500 times, stealing sensitive info. Supply chain risk for client-side web security.
  • Mini Shai-Hulud worm: npm and PyPI supply chain campaign — TeamPCP group compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations. Targets developer and cloud credentials. Any system with affected packages must be treated as fully compromised.
  • CrashStealer macOS malware uses notarized dropper to bypass Gatekeeper — Native C++ macOS info stealer masquerading as an Apple crash-reporting tool. Harvests credentials, keychain data, crypto wallets. Validates the victim's login password locally before exfiltration.
  • Verizon DBIR 2026 key findings — Vulnerability exploitation is now the top initial access vector (31% of breaches). Median patch time increased by 11 days. AI-driven vulnerability discovery and exploitation accelerate risk, emphasizing the need for continuous exposure management.

📋 Vendor Bulletins & Advisories

  • Microsoft Entra ID security update — Passkeys are now the default authentication method, with a new model for SMS and voice authentication. Prepare for transition to passwordless sign-in.
  • Oracle June 2026 CSPU: 243 CVEs, 122 critical — Monthly Critical Security Patch Update addresses 243 CVEs across Oracle products, with Fusion Middleware receiving the most patches (106). Immediate patching recommended for critical fixes.
  • Microsoft June 2026 Patch Tuesday: 198 CVEs, 32 critical, 3 zero-days — Largest Patch Tuesday release to date, including fixes for zero-days and critical vulnerabilities across .NET, Azure, Active Directory, and more. Urgent deployment advised.
  • Oracle May 2026 CSPU: 35 CVEs, 11 critical — Monthly update with critical patches for Oracle E-Business Suite and other products.
  • Microsoft May 2026 Patch Tuesday: 118 CVEs — Includes patches for Azure services, .NET, and Microsoft Edge. No zero-days exploited in the wild this cycle.

📰 Lesser-Known / Under-Reported

  • Google & Microsoft remove ModHeader extension (1.6M installs) — Hidden dormant browsing-history collector found in the ModHeader extension. No evidence of data exfiltration, but the extension was removed from the Chrome and Edge stores as a precaution.
  • "Yellow Teams" shaping AI security — Emerging practice where engineers build AI-based offensive and defensive tools to test AI's cybersecurity potential and threats. Early insights into the evolution of AI security operations.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check