XenShell is a JavaServer Pages (JSP) web shell used in the exploitation of Cisco Catalyst SD-WAN Manager vulnerabilities during widespread intrusion activity observed in 2026. It is associated with publicly released proof-of-concept code from ZeroZenX Labs and was deployed by multiple threat clusters following exploitation of a vulnerability chain involving CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. XenShell provides attackers with post-compromise command execution on affected systems and serves as a foothold for follow-on activity.
The malware was observed on compromised Cisco SD-WAN Manager environments, where operators used it to run arbitrary bash commands after gaining unauthenticated access through the vulnerable management platform. XenShell appeared alongside other JSP web shells such as Godzilla and Behinder, as well as additional tooling including Sliver, AdaptixC2-derived implants, cryptocurrency miners, proxying tools, and credential-stealing scripts. This indicates its role as a lightweight post-exploitation access mechanism within broader opportunistic and multi-cluster exploitation activity rather than as a uniquely attributed espionage platform.
Observed campaigns affected Cisco SD-WAN infrastructure across on-premises and cloud deployments. Cisco Talos linked at least 10 distinct threat clusters to exploitation of the SD-WAN Manager flaws, with XenShell specifically appearing in one of those clusters. The broader activity included credential theft targeting administrative material, JWT authentication material, and cloud credentials, but XenShell itself is directly supported as a web shell used for persistence and command execution on compromised systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JSP-based web shell deployed on compromised Cisco SD-WAN systems to enable arbitrary bash command execution.
A webshell observed in exploitation of Cisco SD-WAN vulnerabilities by additional threat clusters.
A JSP-based webshell used after successful exploitation of Cisco Catalyst SD-WAN Manager vulnerabilities to execute bash commands on the affected system.
A JSP-based webshell deployed after exploitation of Cisco Catalyst SD-WAN vulnerabilities, allowing attackers to execute bash commands on affected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.