Find notable cyber news and cases, enriched with sources, timelines, and signals.

Static Tundra Cisco CVE-2018-0171 active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 9
2 unique sources, 4 articles

Summary

Hide ▲

Static Tundra is an ongoing exploitation wave against CVE-2018-0171 in Cisco IOS and Cisco IOS XE devices, using weak or default SNMP settings and Cisco Smart Install to reach critical infrastructure and other organizations. In August 2025, the FBI warned that the group had been targeting critical infrastructure with the flaw since November 2021, and the latest joint advisory from NSA, FBI, CISA and other agencies says the actors scan internet-facing routers, copy configuration files, and exfiltrate them via TFTP to actor-controlled servers. The activity remains tied to FSB Center 16 and continues to affect exposed network devices across multiple sectors.

Related Happenings

Cisco security patch release for CVE-2026-20184

Security Patch Release
H score44 First: 16.04.2026 14:27 Last: 16.04.2026 14:27 Sources 1

About this happening: Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...

Cisco ISE and ISE-PIC input-validation RCE (CVE-2026-20147)

Vulnerability
H score39 First: 16.04.2026 14:27 Last: 16.04.2026 14:27 Sources 1

About this happening: Cisco's CVE-2026-20147 flaw in Identity Services Engine (ISE) and ISE-PIC can let authenticated admins reach remote code execution by sending crafted HTTP reques...

Cisco Catalyst SD-WAN active exploitation wave

Exploitation Wave
H score57 First: 05.03.2026 14:15 Last: 05.03.2026 14:15 Sources 1

About this happening: Cisco confirmed active exploitation of two recently patched Catalyst SD-WAN vulnerabilities, creating immediate risk for exposed systems that have not been fully remed...

Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)

Security Patch Release
H score58 First: 04.03.2026 21:12 Last: 04.03.2026 21:12 Sources 1

About this happening: Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...

Latest development: 20.03.2026 17:09

CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.

Cisco Secure Firewall Management Center (FMC) authentication bypass and RCE flaws (multiple vulnerabilities)

Vulnerability
H score59 First: 04.03.2026 21:12 Last: 04.03.2026 21:12 Sources 1

About this happening: Cisco Secure Firewall Management Center (FMC) has two maximum-severity flaws, CVE-2026-20079 and CVE-2026-20131, that can let unauthenticated attackers take ov...

Latest development: 20.03.2026 17:09

CISA ordered Federal Civilian Executive Branch agencies to patch CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco and Amazon threat intelligence reported active exploitation; Cisco updated its bulletin on March 18 to warn that the vulnerability in the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root, and CISA added the CVE to its KEV catalog as known to be used in ransomware campaigns.

Timeline

  1. 21.08.2025 15:04 4 articles · 10mo ago

    Static Tundra exploitation campaign expands across sectors

    Campaign Scope Update

    FSB-linked Static Tundra is exploiting CVE-2018-0171 in Cisco IOS and Cisco IOS XE devices to target critical infrastructure and other organizations worldwide, with Cisco Talos reporting aggressive compromise attempts against unpatched telecommunications, higher education, and manufacturing organizations across North America, Asia, Africa, and Europe. The activity includes collection of configuration files from thousands of networking devices tied to US entities, unauthorized configuration changes on some vulnerable devices, reconnaissance inside victim networks, custom SNMP tooling for persistence and evasion, and use of the SYNful Knock firmware implant.

    Show sources