Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Essential information
- Published
- 14/05/2026 22:10
- Modified
- 15/05/2026 18:45
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- adaptixc2 authentication bypass behinder cisco credential theft cryptocurrency mining cve-2026-20122 cve-2026-20127 cve-2026-20128 cve-2026-20133 cve-2026-20182 godzilla gsocket kscan nimplant sd-wan sliver webshells xenshell xmrig
- Tags
- 2026-05-14 CVE-2026-20122 CVE-2026-20127 CVE-2026-20128 CVE-2026-20133 CVE-2026-20182 adaptixc2 authentication bypass behinder cisco credential-theft cryptocurrency mining godzilla gsocket kscan nimplant sd-wan sliver webshells xenshell xmrig
- Related entities
- 7 vulnerabilities (cve), 26 indicators, 26 observables, 1 intrusion sets (apt), 20 techniques (mitre), 9 malware, 2 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (7)
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This …
- Attack vector
- Network
- Complexity
- Low
- Published
- 25/02/2026
- Modified
- 15/05/2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/02/2026
- Modified
- 18/06/2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 14/05/2026
- Modified
- 18/06/2026
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/02/2026
- Modified
- 15/05/2026
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain …
- Attack vector
- Local
- Complexity
- High
- Published
- 25/02/2026
- Modified
- 15/05/2026
Indicators (26)
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 13/06/2026 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 19/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 11/05/2027 · Source: AlienVault
Observables (26)
-
https://1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev/download -
http://83.229.126.195:8081/config.json -
96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46 -
0c87871642f84e09e8d3fb23ec36bf55601323e31151a7017a85dbec929cf15d -
18d77c9c5bbb5b9d5bdfd366fdfcf26bad9e64c63ca865fad711bcce8e3d5a80 -
d94f75a70b5cabaf786ac57177ed841732e62bdcc9a29e06e5b41d9be567bcfa -
17302d903baf182f94dc3be40ab1e0874dd0eb2ec5255bf9131fd53591efe925 -
0ed72d52347bfe4a78afff8a6982a64050c8fc86d8957a20eeb3e0f3f5342ed0 -
b0f51b098842cd630097b462aab0ec357e2c7824af37cca6d08165265da2c2d3 -
5bc5998161056b7c8f70c9724d8a63abc7ff8c3843b91c30cffab0899e39b7f8 -
02654acfb21f83485393ba8b14bd8862b919b9ec966fc6768f6aac1338a45ee8 -
72f570ce97de3eaaffef33d90b0c337a153fc9690cc34ee207b557d868360060
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (20)
Malware (9)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family
-
Family
-
Family
-
Family
-
Family
Others (2)
-
1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev
-
a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev