Cisco IOS XE — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
24
occurrences
First Seen
October 31, 2025
Last Seen
August 6, 2026

Cisco IOS XE is a network operating system used on Cisco routers and switches.

Overview

Cisco IOS XE is a network operating system used on Cisco routers and switches. Recent activity shows an old vulnerability, named BadCandy, being actively exploited to implant the BADCANDY webshell on exposed devices, enabling persisted remote access and control of network infrastructure. The incidents have prompted warnings from Australian authorities, underscoring the risk to unpatched IOS XE deployments and the potential impact on critical networks.

Related Threat Clusters

Recent Intelligence Reports

  • NatJack exploits put NAT security assumptions to the test at Black Hat — Csoonline · August 6, 2026
  • Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws — Gbhackers · August 6, 2026
  • Cisco Talos, which tracks the same group under the alias Static Tundra — blog.talosintelligence.com · July 14, 2026
  • FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years — Techtimes · July 13, 2026
  • US authorities warn that state — Cybersecuritydive · July 13, 2026
  • US and allies warn of Russian critical infrastructure attacks — Bleepingcomputer · July 13, 2026
  • Chinese cyberspies breach Singapore's four largest telcos — Bleepingcomputer · February 9, 2026
  • Salt Typhoon and the Widespread Hacking of Western Telecoms Networks — Vocal.Media · January 31, 2026

CVSS v3.1 Breakdown