Static Tundra Cisco CVE-2018-0171 active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Static Tundra is an ongoing exploitation wave against CVE-2018-0171 in Cisco IOS and Cisco IOS XE devices, using weak or default SNMP settings and Cisco Smart Install to reach critical infrastructure and other organizations. In August 2025, the FBI warned that the group had been targeting critical infrastructure with the flaw since November 2021, and the latest joint advisory from NSA, FBI, CISA and other agencies says the actors scan internet-facing routers, copy configuration files, and exfiltrate them via TFTP to actor-controlled servers. The activity remains tied to FSB Center 16 and continues to affect exposed network devices across multiple sectors.
Related Happenings
Cisco security patch release for CVE-2026-20184
Security Patch Release
H score44
First: 16.04.2026 14:27
Last: 16.04.2026 14:27
Sources 1
About this happening:
Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Cisco security patch release for CVE-2026-20184
Security Patch ReleaseAbout this happening: Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Cisco ISE and ISE-PIC input-validation RCE (CVE-2026-20147)
Vulnerability
H score39
First: 16.04.2026 14:27
Last: 16.04.2026 14:27
Sources 1
About this happening:
Cisco's CVE-2026-20147 flaw in Identity Services Engine (ISE) and ISE-PIC can let authenticated admins reach remote code execution by sending crafted HTTP reques...
Cisco ISE and ISE-PIC input-validation RCE (CVE-2026-20147)
VulnerabilityAbout this happening: Cisco's CVE-2026-20147 flaw in Identity Services Engine (ISE) and ISE-PIC can let authenticated admins reach remote code execution by sending crafted HTTP reques...
Cisco Catalyst SD-WAN active exploitation wave
Exploitation Wave
H score57
First: 05.03.2026 14:15
Last: 05.03.2026 14:15
Sources 1
About this happening:
Cisco confirmed active exploitation of two recently patched Catalyst SD-WAN vulnerabilities, creating immediate risk for exposed systems that have not been fully remed...
Cisco Catalyst SD-WAN active exploitation wave
Exploitation WaveAbout this happening: Cisco confirmed active exploitation of two recently patched Catalyst SD-WAN vulnerabilities, creating immediate risk for exposed systems that have not been fully remed...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch Release
H score58
First: 04.03.2026 21:12
Last: 04.03.2026 21:12
Sources 1
About this happening:
Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch ReleaseAbout this happening: Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...
Latest development: 20.03.2026 17:09
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.
Cisco Secure Firewall Management Center (FMC) authentication bypass and RCE flaws (multiple vulnerabilities)
Vulnerability
H score59
First: 04.03.2026 21:12
Last: 04.03.2026 21:12
Sources 1
About this happening:
Cisco Secure Firewall Management Center (FMC) has two maximum-severity flaws, CVE-2026-20079 and CVE-2026-20131, that can let unauthenticated attackers take ov...
Cisco Secure Firewall Management Center (FMC) authentication bypass and RCE flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Cisco Secure Firewall Management Center (FMC) has two maximum-severity flaws, CVE-2026-20079 and CVE-2026-20131, that can let unauthenticated attackers take ov...
Latest development: 20.03.2026 17:09
CISA ordered Federal Civilian Executive Branch agencies to patch CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco and Amazon threat intelligence reported active exploitation; Cisco updated its bulletin on March 18 to warn that the vulnerability in the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root, and CISA added the CVE to its KEV catalog as known to be used in ransomware campaigns.
Timeline
-
21.08.2025 15:04 4 articles · 10mo ago
Static Tundra exploitation campaign expands across sectors
Campaign Scope UpdateFSB-linked Static Tundra is exploiting CVE-2018-0171 in Cisco IOS and Cisco IOS XE devices to target critical infrastructure and other organizations worldwide, with Cisco Talos reporting aggressive compromise attempts against unpatched telecommunications, higher education, and manufacturing organizations across North America, Asia, Africa, and Europe. The activity includes collection of configuration files from thousands of networking devices tied to US entities, unauthorized configuration changes on some vulnerable devices, reconnaissance inside victim networks, custom SNMP tooling for persistence and evasion, and use of the SYNful Knock firmware implant.
Show sources
- FBI warns of Russian hackers exploiting 7-year-old Cisco flaw — www.bleepingcomputer.com — 21.08.2025 15:04
- US offers $10 million bounty for info on Russian FSB hackers — www.bleepingcomputer.com — 03.09.2025 22:01
- US and allies warn of Russian critical infrastructure attacks — www.bleepingcomputer.com — 13.07.2026 12:32
- Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns — www.infosecurity-magazine.com — 13.07.2026 13:40