Observed Signal · Feb 26, 2026 · Vulnerability Disclosure · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Critical Cisco Bug Exploited Since 2023, Global Alert Issued
Cisco disclosed a critical vulnerability (CVSS 10.0) in its Catalyst SD‑WAN product family that allows remote attackers to gain full, persistent privileged access to affected devices. Cisco’s researchers found evidence of exploitation dating back to 2023, and some impacted organizations are described as critical infrastructure. Governments including Australia, Canada, New Zealand, the United Kingdom and the United States issued warnings; U.S. agency CISA ordered civilian federal agencies to patch by the end of the specified Friday citing imminent threat. Cisco and governments did not publicly attribute the attacks to a named threat actor, though Cisco tracked a cluster of activity as UAT‑8616. The disclosure follows a December advisory for another actively exploited Cisco vulnerability in Async software.
Critical (CVSS 10.0) remotely exploitable vulnerability in a widely deployed enterprise networking product with evidence of multi-year exploitation, government alerts and a CISA patch directive—poses high operational and data‑security risk across industries.
Track Synamedia Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Cisco disclosed a critical vulnerability in Catalyst SD‑WAN products with a maximum CVSS severity score of 10.0.
- Cisco researchers traced evidence of exploitation as far back as 2023.
- The flaw enables remote attackers to gain highest-level permissions and maintain persistent, hidden access inside victim networks.
- Australia, Canada, New Zealand, the United Kingdom and the United States issued alerts; CISA ordered federal civilian agencies to patch by end-of-day Friday.
- Cisco and governments did not publicly attribute the activity to a specific threat group; one cluster was tracked as UAT-8616.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Cisco patches CVSS 10.0 Secure Workload authentication bypass
Cisco released emergency patches addressing a maximum-severity authentication-bypass vulnerability in its Secure Workload platform (tracked as CVE-2026-20223) that earned a CVSS 10.0 score. The flaw allows unauthenticated remote attackers to gain Site Admin privileges by sending specially crafted requests to Secure Workload's REST API, bypassing authentication. The vulnerability affects both SaaS-hosted and on-premises deployments, can enable cross-tenant access to sensitive telemetry and configuration, and has no known workaround — Cisco recommends applying the fixes immediately. Security publishers noted this is one of several 'perfect 10' bugs disclosed for Cisco in 2026 and emphasized the broad impact on enterprises that use Secure Workload as part of zero-trust and micro-segmentation architectures.
CISA flags three actively exploited Linux kernel flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog (KEV), indicating they are being actively exploited. The flaws, tracked as CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, are rated as 'critical' or 'high' severity. Red Hat has confirmed exploitation via publicly known exploits. The vulnerabilities can lead to system crashes, privilege escalation, and remote code execution. CISA has ordered US federal agencies to patch affected systems within three days or temporarily take them offline. Patches are available in the kernel, and administrators are urged to apply them urgently. No details on the threat actors or targets have been disclosed yet.
Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
New blog post published September 28, 2026: Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
