Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7 — dropped from § 2, gate not cleared)
cve · CVE-2026-20034
Coverage timeline
2
first 2026-05-10 → last 2026-05-10
Briefs
2
2 distinct
Sources cited
65
37 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
Source distribution
- attack.mitre.org9 (14%)
- sec.cloudapps.cisco.com7 (11%)
- blog.talosintelligence.com6 (9%)
- bleepingcomputer.com4 (6%)
- thehackernews.com3 (5%)
- theregister.com3 (5%)
- security-hub.ncsc.admin.ch2 (3%)
- securityweek.com2 (3%)
- other29 (45%)
External references
All cited sources (65)
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRT, 2026-06-03https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx
- sec.cloudapps.cisco.comprimaryinlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- attack.mitre.orginlineT1021.001 Remote Services: Remote Desktop Protocolhttps://attack.mitre.org/techniques/T1021/001/
- attack.mitre.orginlineT1047 Windows Management Instrumentationhttps://attack.mitre.org/techniques/T1047/
- attack.mitre.orginlineT1059 Command and Scripting Interpreterhttps://attack.mitre.org/techniques/T1059/
- attack.mitre.orginlineT1078.004 Valid Accounts: Cloud Accountshttps://attack.mitre.org/techniques/T1078/004/
- attack.mitre.orginlineT1133 External Remote Serviceshttps://attack.mitre.org/techniques/T1133/
- attack.mitre.orginlineT1190https://attack.mitre.org/techniques/T1190/
- attack.mitre.orginlineT1486 Data Encrypted for Impacthttps://attack.mitre.org/techniques/T1486/
- attack.mitre.orginlineT1505.003 Server Software Component: Web Shellhttps://attack.mitre.org/techniques/T1505/003/
- attack.mitre.orginlineT1567 Exfiltration Over Web Servicehttps://attack.mitre.org/techniques/T1567/
- bankinfosecurity.cominlineBankInfoSecurity, 2026-05-11https://www.bankinfosecurity.com/tables-turned-gentlemen-ransomware-group-suffers-data-leak-a-31654
- bleepingcomputer.cominlineBleepingComputer, 2026-05-29https://www.bleepingcomputer.com/news/security/california-ag-sues-23andme-over-2023-breach-exposing-health-data/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-15https://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-23https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputer 2026-05-05https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/
- blick.chinlineBlick.ch, 2026-05-07https://www.blick.ch/fr/suisse/romande/cyberattaque-le-groupe-romand-3r-de-radiologie-cible-id21930477.html
- blog.checkpoint.cominlineCheck Point bloghttps://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk
- blog.talosintelligence.cominlineCisco Talos, 2026-05-05https://blog.talosintelligence.com/cloudz-pheno-infostealer/
- blog.talosintelligence.cominlineCisco Talos — DICOM / Orthanc heap analysishttps://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heap/
- blog.talosintelligence.cominlineCisco Taloshttps://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/
- blog.talosintelligence.cominlineCisco Talos UAT-8616https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- blog.talosintelligence.cominlineCisco Talos — UAT-8302https://blog.talosintelligence.com/uat-8302/
- blog.talosintelligence.cominlineCisco Talos, 2026https://blog.talosintelligence.com/uat-8616-sd-wan/
- cisa.govinlineCISA ED-26-03https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems
- cloud.google.cominlineMandiant, 2026-06-05https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/
- cnil.frinlineCNIL — €5M IQVIA finehttps://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia
- comparitech.cominlineComparitech Q1 2026 Healthcare, 2026-04-29https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/
- cyber.gov.auinlineACSC hunt guide, 2026-02-25https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf
- cybermaxx.cominlineCyberMaxx Q1 2026https://www.cybermaxx.com/resources/ransomware-research-report-q1-2026-audio-blog-interview/
- elastic.coinlineElastic Security Labs 2026-05-07https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
- github.cominlineGitHub `Bedrock-Safeguard/gentlemen-decryptor`https://github.com/Bedrock-Safeguard/gentlemen-decryptor
- groupe3r.chinlineGroupe 3R victim statement, 2026-04-30https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/
- huntress.cominlineHuntresshttps://www.huntress.com/blog/malspam-to-deskcvb-rat-delivery-chain-analysis
- ictjournal.chinlineICTjournal.ch, 2026-05-06https://www.ictjournal.ch/news/2026-05-06/le-reseau-radiologique-romand-a-nouveau-victime-dune-cyberattaque-ses-systemes
- lumen.cominlineLumen Black Lotus Labs, 2026-06-10https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation
- microsoft.cominlineMicrosoft Security Blog 2026-05-04https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
- nvd.nist.govinlineNVD CVSS 6.5https://nvd.nist.gov/vuln/detail/CVE-2026-20262
- oag.ca.govinlineCalifornia OAG, 2026-05-28https://oag.ca.gov/news/press-releases/attorney-general-bonta-sues-chrome-holding-co-formerly-known-23andme-over-2023
- oasis.securityinlineOasis Security 2026-05-07https://www.oasis.security/blog/cline-kanban-websocket-hijack
- pgadmin.orginlinepgAdminhttps://www.pgadmin.org/docs/pgadmin4/9.16/release_notes_9_16.html
- politie.nlinlinePolitiehttps://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html
- rapid7.cominlineRapid7, 2026-05-14https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/
- research.checkpoint.cominlineCheck Pointhttps://research.checkpoint.com/2026/thus-spoke-the-gentlemen/
- sansec.ioinlineSansechttps://sansec.io/research/optinmonster-supply-chain-attack
- security-hub.ncsc.admin.chinlineNCSC-CH 12579https://security-hub.ncsc.admin.ch/#/posts/12579
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub, 2026-05-21https://security-hub.ncsc.admin.ch/#/posts/12588
- securityweek.cominlineSecurityWeek, 2026-05-15https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/
- securityweek.cominlineSecurityWeek, 2026-06-18https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/
- sygnia.coinlineSygnia — Velvet Ant prior reportinghttps://www.sygnia.co/blog/china-nexus-threat-group-velvet-ant/
- thehackernews.cominlineThe Hacker News, 2026-05-05https://thehackernews.com/2026/05/china-linked-uat-8302-targets.html
- thehackernews.cominlineThe Hacker News 2026-05-04https://thehackernews.com/2026/05/progress-patches-critical-moveit.html
- thehackernews.cominlineThe Hacker News, 2026-06-10https://thehackernews.com/2026/06/china-linked-jdy-botnet-expands-to-1500.html
- therecord.mediainlineRecorded Future News, 2026-05-19https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage
- theregister.cominlineThe Register, 2026-05-29https://www.theregister.com/legal/2026/05/29/rob-bonta-sues-23andmes-new-owners-over-2023-breach/5248565
- theregister.cominlineThe Registerhttps://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916
- theregister.cominlineThe Registerhttps://www.theregister.com/security/2026/05/21/cisco-serves-up-yet-another-perfect-10-bug-with-secure-workload-admin-flaw/5244012
- upguard.cominlineUpGuardhttps://www.upguard.com/news/world-food-programme-data-breach-2026-06-02
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1989https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1989
Items in briefs about Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7 — dropped from § 2, gate not cleared)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.