Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposurerapid-weaponizationidentity-authentication-vulnerability

Internet-Scale Scanning and Exploitation Pressure on Edge Network Devices (Cisco SD-WAN, SonicWall SSL VPN)

Updated 3mo agoFirst seen Mar 2, 20263 sources

Security monitoring and reporting highlighted escalating attacker focus on internet-exposed edge infrastructure, including active exploitation of a maximum-severity Cisco SD-WAN flaw and large-scale reconnaissance against SonicWall firewalls. Cisco disclosed CVE-2026-20127 (CVSS 10.0) affecting Cisco Catalyst SD-WAN Controller (vSmart) and Catalyst SD-WAN Manager (vManage), describing in-the-wild exploitation dating back to 2023 that enables unauthenticated authentication bypass leading to administrative privileges via crafted requests; Cisco attributes discovery to ASD-ACSC and tracks related activity as UAT-8616.

Separately, GreyNoise-tracked activity showed a coordinated scanning campaign against SonicWall SonicOS devices using 4,000+ unique IPs to enumerate targets—primarily probing a SonicOS REST API endpoint used to determine whether SSL VPN is enabled (a common precursor to follow-on credential attacks and exploitation). The campaign generated 84,142 scanning sessions over a four-day window and was assessed as a continuation/escalation of similar late-2025 scanning that targeted both Palo Alto and SonicWall VPN infrastructure, reinforcing the likelihood of an impending exploitation wave against exposed and unpatched perimeter devices.

Share:
Internet-Scale Scanning and Exploitation Pressure on Edge Network Devices (Cisco SD-WAN, SonicWall SSL VPN)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 2, 20264mo ago

CISA issues emergency directive over Cisco SD-WAN flaw

Following reports of active exploitation of the maximum-severity Cisco Catalyst SD-WAN Controller flaw CVE-2026-20127, CISA issued an emergency directive. The directive reflected the severity of the unauthenticated authentication-bypass issue and the risk to affected environments.

Anthropic Claude Code flaws disclosed

Check Point Research disclosed critical vulnerabilities in Anthropic's Claude Code that could allow remote code execution and theft of API keys through malicious project configurations. The issues were highlighted publicly in threat reporting on March 2, 2026.

Cisco SD-WAN zero-day reportedly exploited for years

Reporting in early March 2026 said the critical Cisco Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20127, had been actively exploited for years. Cisco associated related activity with threat cluster UAT-8616.

Feb 22, 20264mo ago

GreyNoise observes large-scale SonicWall SonicOS scanning

Between February 22 and February 25, 2026, GreyNoise recorded 84,142 scanning sessions from 4,305 unique IP addresses across 20 autonomous systems targeting internet-exposed SonicWall SonicOS devices. Most activity probed a REST API endpoint used to determine whether SSL VPN was enabled, suggesting target selection ahead of exploitation.

Dec 1, 20257mo ago

Mass scanning campaign targets VPN infrastructure

In December 2025, a reconnaissance campaign conducted millions of scans against Palo Alto and SonicWall VPN infrastructure using shared client fingerprints. Later reporting linked the February 2026 SonicWall activity to this earlier campaign as an escalation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

153 LINKEDOpen in app
Vulnerabilities
42 linked
Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, and ValidatorRoundcube Webmail Post-Auth RCE via PHP Object DeserializationCode Injection in Anthropic Claude Code startup trust dialogPrivilege Escalation in Cisco SD-WAN Software CLIRoundcube Webmail SVG animate tag XSSUnauthenticated Deserialization RCE in SolarWinds Web Help DeskAuthentication Bypass in SolarWinds Web Help DeskAuthentication Bypass in SolarWinds Web Help DeskAuthentication Bypass in SonicWall SonicOS SSLVPNStack-based buffer overflow in Tenda AC1206 /goform/setMacFilterCfg (formSetMacFilterCfg)Unauthorized read-only access in SonicWall SMA100 (SRA)SQL Injection in SonicWall Secure Remote Access (SRA)Command Injection in Gardyn Home KitAuthenticated RCE in n8n Workflow Expression EvaluationHost Header Injection in Undertow HTTP Server CoreGNU Inetutils telnetd remote authentication bypass via USER argument injectionPDF object injection in jsPDF addJS (CVE-2026-25755)HTTP Request Smuggling in Akamai Ghost CDN edge serversScript/HTML Injection in Google Chrome DevTools via Malicious ExtensionOut-of-bounds read in Google Chrome MediaOut-of-bounds read/write in Tint in Google Chrome on macOSPost-authentication command injection in Zyxel VMG3625-T50B TR-369 certificate download CGIType Confusion RCE in SolarWinds Serv-UBroken access control in SolarWinds Serv-U allowing system admin creation and privileged code executionUnauthenticated Command Injection in Zyxel EX3510-B0 UPnPType Confusion RCE in SolarWinds Serv-UPrivileged Native Code Execution via IDOR in SolarWinds Serv-UAuthenticated Command Injection in Zyxel EX3301-T0 Log File Download CGIStored XSS in VMware Aria Operations Custom BenchmarksUnauthenticated Command Injection RCE in VMware Aria OperationsPrivilege Escalation in VMware Aria OperationsIntegrity validation bypass in CPSD CryptoPro Secure Disk pre-boot Linux environmentFreeBSD jail/chroot escape via directory file descriptor exchange across sibling jailsTrend Micro Apex One Management Console Directory Traversal RCEDirectory Traversal RCE in Trend Micro Apex One Management ConsoleArbitrary File Overwrite in Cisco Catalyst SD-WAN Manager APIInformation Disclosure in Cisco Catalyst SD-WAN Manager DCACisco Catalyst SD-WAN Manager REST API Privilege EscalationHard-coded Administrative Credentials Exposure in Gardyn IoT HubSSRF in Angular SSR request handling pipelineUnauthenticated Root RCE in Juniper Junos OS Evolved PTX On-Box Anomaly DetectionUnauthenticated RCE in ServiceNow AI Platform Sandbox
Affected products
21 linked
Claude CodeRoundcube WebmailWordpressFacebookAndroidTelegramSonicosGithubJunos OsBitlockerServ-UChatgptServ-UConnect SecureServ-UChatgptAndroidApex OneFreebsdServicenow Ai PlatformN8n
Organizations
46 linked
Cisco SystemsCheck Point Software TechnologiesDeepseekAnthropicSolarWindsOpenaiMiniMaxCpanelMoonshot AIWynn ResortsTransport Workers Union of America Local 100UFP TechnologiesManoManoGreyNoiseSonicwallTrend MicroAkamai TechnologiesCryptoproJuniper NetworksTruffle SecurityF6TendaZyxel CommunicationsLAB52Palo Alto NetworksSamsung ElectronicsKasperskyQianxinHudson RockVaronisMeta PlatformsIvantiServicenowBroadcomPraetorianOrca SecurityTelegramHewlett Packard EnterprisexAIGroup-IBGoogleBright DataGardynGambit SecurityIntegral Ad ScienceIIJ-SECT
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.