2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10 episode artwork

EPISODE · May 16, 2026 · 22 MIN

2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10

from Cyber Threat Brief

Show Notes - 2026-05-16 Stories Covered: - 2026-05-16 - Today: - Cisco SD-WAN Authentication Bypass Zero-Day (CVE-2026-20182) (https://cyberscoop.com/cisco-sd-wan-zero-day-exploited/) - Microsoft Exchange Server Zero-Day (CVE-2026-42897) (https://www.securityweek.com/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild/) - BlackFile (UNC6671) Targets Microsoft 365 and Okta via Vishing (https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/) - node-ipc npm Package Compromised with Credential Stealer (https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/) - OpenClaw Vulnerabilities Allow Data Theft and Privilege Escalation (https://thehackernews.com/2026/05/four-openclaw-flaws-enable-data-theft.html) - TanStack Supply Chain Attack Hits OpenAI (https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html) - Pwn2Own Berlin 2026: Microsoft Exchange, Windows 11 Hacked (https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/) - REMUS Infostealer Malware-as-a-Service Operation (https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/) - AI Agents Used to Discover and Exploit Zero-Days (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-20-7/) - Microsoft Edge to Stop Loading Passwords into Memory on Startup (https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/) - WordPress Avada Builder Plugin Flaws (https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/) - WordPress Funnel Builder Plugin Exploited for Credit Card Theft (https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/) - PostgreSQL Multiple Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6478) - Additional CVEs (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43490) CVEs Referenced: CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-40460, CVE-2026-42897, CVE-2026-43490, CVE-2026-44112, CVE-2026-44113, CVE-2026-44115, CVE-2026-44118, CVE-2026-44431, CVE-2026-44662, CVE-2026-44673, CVE-2026-46333, CVE-2026-4782, CVE-2026-4798, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6637, CVE-2026-6638 Indicators of Compromise: Domains: enrollms[.]com, passkeyms[.]com, setupsso[.]com, setupsso[.]com., sh[.]azurestaticprovider, bt[.]node, azurestaticprovider[.]net, node[.]js, analytics-reports[.]com, protect-wss[.]com IPs: 3.15.0.3 Full brief: https://carolinacleartech.com/brief/2026-05-16/

Episode metadata supplied by the publisher feed · Published May 16, 2026

Embed this episode

Show Notes - 2026-05-16 Stories Covered: - 2026-05-16 - Today: - Cisco SD-WAN Authentication Bypass Zero-Day (CVE-2026-20182) (https://cyberscoop.com/cisco-sd-wan-zero-day-exploited/) - Microsoft Exchange Server Zero-Day (CVE-2026-42897) (https://www.securityweek.com/microsoft-warns-of-exchange-ser

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10

0:00 22:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 22 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 16, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!