Security monitoring and reporting highlighted escalating attacker focus on internet-exposed edge infrastructure, including active exploitation of a maximum-severity Cisco SD-WAN flaw and large-scale reconnaissance against SonicWall firewalls. Cisco disclosed CVE-2026-20127 (CVSS 10.0) affecting Cisco Catalyst SD-WAN Controller (vSmart) and Catalyst SD-WAN Manager (vManage), describing in-the-wild exploitation dating back to 2023 that enables unauthenticated authentication bypass leading to administrative privileges via crafted requests; Cisco attributes discovery to ASD-ACSC and tracks related activity as UAT-8616.
Separately, GreyNoise-tracked activity showed a coordinated scanning campaign against SonicWall SonicOS devices using 4,000+ unique IPs to enumerate targets—primarily probing a SonicOS REST API endpoint used to determine whether SSL VPN is enabled (a common precursor to follow-on credential attacks and exploitation). The campaign generated 84,142 scanning sessions over a four-day window and was assessed as a continuation/escalation of similar late-2025 scanning that targeted both Palo Alto and SonicWall VPN infrastructure, reinforcing the likelihood of an impending exploitation wave against exposed and unpatched perimeter devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following reports of active exploitation of the maximum-severity Cisco Catalyst SD-WAN Controller flaw CVE-2026-20127, CISA issued an emergency directive. The directive reflected the severity of the unauthenticated authentication-bypass issue and the risk to affected environments.
Check Point Research disclosed critical vulnerabilities in Anthropic's Claude Code that could allow remote code execution and theft of API keys through malicious project configurations. The issues were highlighted publicly in threat reporting on March 2, 2026.
Reporting in early March 2026 said the critical Cisco Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20127, had been actively exploited for years. Cisco associated related activity with threat cluster UAT-8616.
Between February 22 and February 25, 2026, GreyNoise recorded 84,142 scanning sessions from 4,305 unique IP addresses across 20 autonomous systems targeting internet-exposed SonicWall SonicOS devices. Most activity probed a REST API endpoint used to determine whether SSL VPN was enabled, suggesting target selection ahead of exploitation.
In December 2025, a reconnaissance campaign conducted millions of scans against Palo Alto and SonicWall VPN infrastructure using shared client fingerprints. Later reporting linked the February 2026 SonicWall activity to this earlier campaign as an escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.