Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Essential information
- Published
- 14/05/2026 22:10
- Modified
- 15/05/2026 18:45
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- adaptixc2 authentication bypass behinder cisco credential theft cryptocurrency mining cve-2026-20122 cve-2026-20127 cve-2026-20128 cve-2026-20133 cve-2026-20182 godzilla gsocket kscan nimplant sd-wan sliver webshells xenshell xmrig
- Tags
- 2026-05-14 CVE-2026-20122 CVE-2026-20127 CVE-2026-20128 CVE-2026-20133 CVE-2026-20182 adaptixc2 authentication bypass behinder cisco credential-theft cryptocurrency mining godzilla gsocket kscan nimplant sd-wan sliver webshells xenshell xmrig
- Related entities
- 7 vulnerabilities (cve), 26 indicators, 26 observables, 1 intrusion sets (apt), 20 techniques (mitre), 9 malware, 2 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (7)
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This …
- Attack vector
- Network
- Complexity
- Low
- Published
- 25/02/2026
- Modified
- 15/05/2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/02/2026
- Modified
- 18/06/2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 14/05/2026
- Modified
- 18/06/2026
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/02/2026
- Modified
- 15/05/2026
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain …
- Attack vector
- Local
- Complexity
- High
- Published
- 25/02/2026
- Modified
- 15/05/2026
Indicators (26)
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 13/06/2026 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 19/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
Observables (26)
-
a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev -
1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev -
89.125.244.33 -
38.60.214.92 -
104.233.156.1 -
89.125.244.51 -
83.229.126.195 -
38.181.52.89 -
71.80.85.135 -
176.65.139.31 -
23.27.143.170 -
47.104.248.7
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (20)
Malware (9)
Others (2)
-
1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev
-
a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev