// ZERO-DAY

// ZERO-DAY

3 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access

Cisco disclosed CVE-2026-20127, a critical zero-day vulnerability (CVSS 10.0) in Cisco Catalyst SD-WAN Controller and Manager that allows unauthenticated remote attackers to bypass authentication and gain admin access. The vulnerability has been actively exploited in the wild since 2023.

US Sanctions Russian Exploit Broker Operation Zero

The US sanctioned a Russian exploit broker operation that acquired eight zero-day exploits from a US defense contractor executive who was jailed for selling them. This represents an actual security incident involving theft and trafficking of zero-day vulnerabilities from a legitimate defense contractor.

Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023

Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN that has been actively exploited in zero-day attacks since 2023, allowing remote attackers to compromise controllers and inject malicious rogue peers into networks.