Cisco Catalyst SD-WAN Manager · Cacti performance and fault management framework · Gogs self-hosted Git service
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-25 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
Mandiant has published technical details on active zero-day exploitation of CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, enabling root-level privilege escalation at a service provider. A coordinated law enforcement operation (Operation Endgame) has disrupted Amadey and StealC infrastructure, recovering 27 million stolen credentials. Google Chrome received an emergency update addressing multiple critical use-after-free vulnerabilities including two Android sandbox escapes. A batch of critical Cacti and Gogs vulnerabilities was published, including pre-authentication SQL injection and authenticated RCE.
CRITICAL VULNERABILITIES
NEW
CVE-2026-20245 (Cisco Catalyst SD-WAN Manager)
- Affected products: Cisco Catalyst SD-WAN Manager (service provider and enterprise deployments)
- Severity: Not yet formally scored; zero-day exploitation confirmed
- EPSS: Not yet available
- Technical detail: Mandiant identified active exploitation of this vulnerability in early 2026 at a service provider. The flaw resides in the device’s file upload feature, which fails to properly filter malicious data. A threat actor with access to a compromised administrative account leveraged the vulnerability to escalate privileges from administrator to root level, subsequently creating rogue root accounts to maintain persistent access. The attack pattern emphasizes operational security, with the actor taking steps to avoid detection throughout the intrusion. SD-WAN Manager is a centralized orchestration platform; root-level compromise provides control over all managed SD-WAN edges.
- Exploitation status: Actively exploited in the wild; zero-day at time of exploitation per Mandiant.
- Remediation: Apply Cisco patches immediately upon release. Audit SD-WAN Manager for unauthorized root accounts and unexpected file uploads. Restrict administrative interface access to trusted management networks. Review Mandiant’s published IOCs for signs of prior compromise.
CVE-2026-39955 / CVE-2026-39938 / CVE-2026-39893 (Cacti)
- Affected products: Cacti performance and fault management framework, versions 1.2.30 and prior
- Severity: CVSS 9.8 (all three)
- EPSS: 0 (newly published; no exploitation data yet)
- Technical detail: Three critical unauthenticated vulnerabilities were published simultaneously. CVE-2026-39955 is a pre-authentication SQL injection via an unanchored FILTER_VALIDATE_REGEXP in graph_view.php, exploitable without any credentials. CVE-2026-39938 is an unauthenticated local file inclusion (LFI) through graph_theme and rrdtool IPC serialization, potentially enabling arbitrary file read and code execution. CVE-2026-39893 involves unsanitized concatenation of the rfilter variable into a RLIKE SQL clause. Cacti is widely deployed in network operations centers and enterprise monitoring environments; unauthenticated exploitation paths make these high-priority. Historical Cacti vulnerabilities have been rapidly weaponized.
- Exploitation status: No confirmed in-the-wild exploitation at time of publication; high risk given Cacti’s exploitation history.
- Remediation: Upgrade to Cacti 1.2.31 immediately. Restrict Cacti web interface access to trusted management networks. Monitor for anomalous SQL errors or unexpected file access in Cacti logs.
CVE-2026-52806 / CVE-2026-52813 (Gogs)
- Affected products: Gogs self-hosted Git service, versions prior to 0.14.3
- Severity: CVE-2026-52806 CVSS 9.9; CVE-2026-52813 CVSS 10.0
- EPSS: 0 (newly published)
- Technical detail: CVE-2026-52806 allows an authenticated user to achieve remote code execution by creating a pull request with a specially crafted payload, exploitable by any user with repository access. CVE-2026-52813 accepts organization names containing path traversal sequences (../), causing repositories to be written to arbitrary filesystem paths, enabling overwrite of sensitive system files. Additional high-severity Gogs flaws published in the same batch include CVE-2026-52811 (symlink bypass in file upload, CVSS 9.0), CVE-2026-52805 (SSRF in repository migration, CVSS 8.7), and CVE-2026-52800 (CSRF in team member management, CVSS 8.8). Organizations self-hosting Gogs for source code management face significant risk.
- Exploitation status: No confirmed in-the-wild exploitation.
- Remediation: Upgrade Gogs to 0.14.3 immediately. If immediate patching is not possible, restrict repository creation and pull request submission to trusted users, and isolate the Gogs instance from untrusted networks.
CVE-2026-13038 / CVE-2026-13032 / CVE-2026-13028 (Google Chrome)
- Affected products: Google Chrome prior to 149.0.7827.197 (all platforms; Android-specific for CVE-2026-13032 and CVE-2026-13028)
- Severity: CVE-2026-13038 CVSS 8.8 (Critical per Chromium); CVE-2026-13032 and CVE-2026-13028 CVSS 9.6 (Critical per Chromium)
- EPSS: 0 (newly published)
- Technical detail: Google released an emergency Chrome update addressing at least nine vulnerabilities. CVE-2026-13038 is a use-after-free in Autofill on Windows allowing arbitrary code execution via a crafted HTML page. CVE-2026-13032 and CVE-2026-13028 are use-after-free flaws in WebGL on Android that could allow a remote attacker to perform a sandbox escape. Additional high-severity use-after-free bugs affect Blink (CVE-2026-13036, CVE-2026-13031), FileSystem (CVE-2026-13027), Bluetooth on Mac (CVE-2026-13035), and Digital Credentials on Mac (CVE-2026-13026). The sandbox escape potential on Android elevates urgency for mobile device fleets.
- Exploitation status: No confirmed in-the-wild exploitation reported at time of publication.
- Remediation: Update Chrome to 149.0.7827.197 or later on all platforms. Enforce Chrome updates via enterprise policy. Prioritize Android device fleets given sandbox escape risk.
CVE-2026-46423 / CVE-2026-45689 / CVE-2026-55666 (Rocket.Chat)
- Affected products: Rocket.Chat prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.7, and 7.10.13 (multiple branches)
- Severity: CVE-2026-46423 CVSS 9.3; CVE-2026-45689 CVSS 9.1; CVE-2026-55666 CVSS 9.3
- EPSS: 0 (newly published)
- Technical detail: Multiple critical vulnerabilities affect Rocket.Chat’s authentication stack. CVE-2026-46423 is a flaw in the SAML service provider implementation allowing authentication bypass. CVE-2026-45689 allows an unauthenticated network attacker to obtain sensitive data. CVE-2026-55666 is an authentication logic flaw in the Apple login handler. Additional SAML-related flaws (CVE-2026-45677, CVE-2026-45688) affect signature verification and CAS login redirect handling. Rocket.Chat is widely deployed in European enterprises and public sector organizations as an internal communications platform; authentication bypass vulnerabilities in this context carry significant data exposure risk.
- Exploitation status: No confirmed in-the-wild exploitation.
- Remediation: Upgrade Rocket.Chat to the latest patched release for your branch (8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.7, or 7.10.13). Prioritize instances with SAML or Apple SSO enabled.
ONGOING
- CVE-2026-20230 (Cisco Unified CM): actively exploited SSRF; patch immediately, restrict management interface.
- CVE-2026-34910/34909/34908 (Ubiquiti UniFi OS): actively exploited; CISA KEV deadline 2026-06-26 — patch today.
- CVE-2025-67038 (Lantronix EDS5000): actively exploited; CISA KEV deadline 2026-06-26 — patch today.
- CVE-2026-11807 (Red Hat Ansible AAP EDA): CVSS 9.6 unauthenticated websocket flaw; apply Red Hat patches.
- CVE-2026-41862 (Spring Statemachine): unsafe deserialization; upgrade to 3.2.5 or 4.0.1.1.
- CVE-2026-20262 (Cisco Catalyst SD-WAN Manager): actively exploited; CISA KEV deadline 2026-06-29.
EUROPEAN ADVISORIES
BSI published a large batch of new and updated advisories on 2026-06-24.
New advisories (NEU): WID-SEC-2026-2041 (Budibase — kritisch): A remote, unauthenticated attacker can exploit a SQL injection vulnerability in Budibase. Organizations using Budibase for internal tooling should apply available updates immediately. WID-SEC-2026-2058 (FasterXML Jackson — hoch): Multiple vulnerabilities allow remote attackers to bypass security controls, manipulate data, disclose information, or cause denial of service. Apply Jackson library updates across all Java application stacks. WID-SEC-2026-2057 (IBM DB2 — hoch): Multiple vulnerabilities enable information disclosure, arbitrary code execution, and denial of service. Apply IBM DB2 patches per vendor guidance. WID-SEC-2026-2056 (Linux Kernel — hoch): Multiple new kernel vulnerabilities enabling denial of service and unspecified attacks. Apply distribution kernel updates. WID-SEC-2026-2055 (Arista EOS — hoch): Multiple vulnerabilities in Arista EOS allow security bypass, privilege escalation, data manipulation, and information disclosure. Apply Arista EOS updates; relevant for organizations using Arista network infrastructure. WID-SEC-2026-2050 (IBM WebSphere Application Server and Liberty — hoch): Multiple vulnerabilities including code execution, XSS, information disclosure, and denial of service. Apply IBM fixes. WID-SEC-2026-2048 (Google Cloud Service Mesh and Envoy Proxy — hoch): Multiple vulnerabilities enabling denial of service, security bypass, and information disclosure. Apply vendor updates. WID-SEC-2026-2044 (CPython — hoch): Multiple vulnerabilities allowing file manipulation, security bypass, and information disclosure. Update Python installations. WID-SEC-2026-2043 (Red Hat Ansible Automation Platform EDA — hoch): Cross-reference: covered in Critical Vulnerabilities as CVE-2026-11807.
Updated advisories (UPDATE): WID-SEC-2026-1639 (Ubiquiti UniFi OS — kritisch): covered in ONGOING above. Multiple Linux Kernel, NGINX, Docker, Golang, GStreamer, Red Hat OpenShift, Kiali, Oracle MySQL, and Red Hat Enterprise Linux advisories updated; apply outstanding patches per vendor guidance.
ACTIVE THREATS AND CAMPAIGNS
NEW — Operation Endgame: Amadey and StealC Disruption A coordinated law enforcement operation involving Europol, Microsoft, Bitdefender, Bitsight, and ESET has disrupted criminal infrastructure powering the Amadey loader and StealC infostealer. Approximately 27 million stolen credentials were recovered. Amadey is a widely used initial access loader that has delivered ransomware, banking trojans, and other malware to enterprise targets across Europe. Organizations should check recovered credential databases (via Have I Been Pwned or law enforcement notification channels) and proactively rotate credentials for accounts that may have been exposed.
NEW — Mistic Backdoor / KongTuke Access Broker A new stealthy backdoor dubbed Mistic has been linked to the KongTuke ransomware access broker. Active targeting has been observed in the insurance, education, IT, and professional services sectors. KongTuke operates as an initial access broker, selling footholds to ransomware affiliates. No public IOCs were available at time of reporting; monitor for unusual persistence mechanisms and lateral movement in affected sectors.
NEW — Malicious Edge Extension (Edgecution) A malicious Microsoft Edge extension named Edgecution has been used in at least one ransomware attack. The extension abuses the Native Messaging API to escape the browser sandbox and deploy a Python-based backdoor. Organizations should audit installed browser extensions across managed endpoints and enforce extension allowlisting via enterprise browser policy.
ONGOING — FortiBleed credential-harvesting campaign: 430,000+ FortiGate devices targeted; rotate all credentials on FortiGate-connected systems. ONGOING — Cisco SD-WAN zero-day (CVE-2026-20245): active exploitation at service providers; see Critical Vulnerabilities.
SECURITY NEWS AND CONTEXT
CVE-2026-20230 exploitation in Cisco Unified CM was confirmed after a public PoC revealed a file-write path to root; this is covered in the ONGOING section above.
Researchers disclosed the Cordyceps CI/CD vulnerability class, affecting over 300 GitHub repositories at major organizations including Microsoft, Google, and Apache, enabling supply-chain attacks via hijacked workflow triggers. Organizations using GitHub Actions should audit pull_request_target workflow configurations.
The US DoJ seized cloud infrastructure linked to HuiOne Group subsidiaries used for cyber scam money laundering; Treasury imposed fresh sanctions on nine individuals and 26 entities tied to Prince Group.
RECOMMENDED ACTIONS
- Patch Ubiquiti UniFi OS and Lantronix EDS5000 today — CISA KEV deadline is 2026-06-26.
- Investigate Cisco Catalyst SD-WAN Manager for CVE-2026-20245 exploitation: audit for rogue root accounts, unexpected file uploads, and apply Cisco patches upon release.
- Upgrade Cacti to 1.2.31 immediately for CVE-2026-39955/39938/39893 (CVSS 9.8, unauthenticated SQL injection and LFI); restrict web interface to trusted networks.
- Upgrade Gogs to 0.14.3 for CVE-2026-52806/52813 (authenticated RCE and path traversal CVSS 9.9/10.0).
- Update Google Chrome to 149.0.7827.197 on all platforms; prioritize Android devices for sandbox escape risk.
- Upgrade Rocket.Chat to the latest patched branch release for CVE-2026-46423/45689/55666 (SAML and auth bypass, CVSS 9.1-9.3).
- Check exposed accounts against Operation Endgame recovered credential data; rotate credentials for potentially affected users.
- Audit Microsoft Edge extensions on managed endpoints; enforce allowlisting to block Edgecution-style Native Messaging abuse.
- Review GitHub Actions workflows for pull_request_target triggers vulnerable to Cordyceps-class supply chain attacks.
- Continue remediation of previously reported items: CVE-2026-20262 (Cisco SD-WAN KEV deadline 2026-06-29), CVE-2026-20230 (Cisco Unified CM), CVE-2026-11807 (Ansible AAP EDA), CVE-2026-41862 (Spring Statemachine), FortiBleed credential rotation.