{"id":54165,"date":"2023-10-17T19:11:13","date_gmt":"2023-10-17T19:11:13","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/ten-thousand-cisco-ios-xe-systems-compromised-zero-day-bug"},"modified":"2023-10-17T19:11:13","modified_gmt":"2023-10-17T19:11:13","slug":"zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/","title":{"rendered":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>A threat actor has already infected thousands of Internet exposed Cisco IOS XE devices with an implant for arbitrary code execution via an as-yet-unpatched maximum severity vulnerability in the operating system.<\/p>\n<p>Cisco disclosed the flaw, identified <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z\" target=\"_blank\" rel=\"noopener\">as CVE-2023-20198<\/a>&nbsp;on Monday, with a warning about <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/critical-unpatched-cisco-zero-day-bug-active-exploit\" target=\"_blank\" rel=\"noopener\">exploit activity in the wild<\/a> targeting the flaw. The bug, which has a severity rating of 10 out of 10 on the CVSS vulnerability-severity&nbsp;scale, is present in the Web UI component of IOS XE.&nbsp;<\/p>\n<p> The company said it had observed an attacker using the vulnerability to gain administrator level privileges on IOS XE devices, and then,&nbsp;in an apparent patch bypass,&nbsp;abusing an older remote code execution (RCE)&nbsp;flaw from 2021 (<a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/csa\/cisco-sa-iosxe-webcmdinjsh-UFJxTgZD.html\" target=\"_blank\" rel=\"noopener\">CVE-2021-1435<\/a>) to drop a Lua-language implant on affected systems&nbsp;.<\/p>\n<p>Now, those attacks appear to have a global footprint.<\/p>\n<p><strong>Unpatched Bug Leads to 10K&nbsp;Infected Cisco Systems<\/strong><\/p>\n<p>Cisco&#8217;s security advisory noted that the company had responded to reports of unusual activity tied to the flaw from multiple customers. But the actual scope of the infections appears to be a lot higher than what was&nbsp;apparent from the advisory.<\/p>\n<p>Jacob Baines, CTO at VulnCheck says his company has fingerprinted at least 10,000 Cisco IOS XE systems with the implant on them\u2014and that&#8217;s from scanning just half of the affected devices that are visible on search engines such as Shodan and Censys.<\/p>\n<p>&#8220;From what we can tell, it doesn\u2019t not appear to be localized,&#8221; Baines says. &#8220;The IPs geolocate to a wide number of countries all over the globe.&#8221;<\/p>\n<p>Baines says it&#8217;s somewhat difficult to determine if the attacks are opportunistic or targeted. On the one hand, opportunistic attacks often involve threat actors using publicly available or researcher-developed proof-of-concept (PoC)&nbsp;exploits.&nbsp;<\/p>\n<p>But that&#8217;s not what has happened with the activity targeted at CVE-2023-20198 so far, he says. &#8220;Not only did the attackers allegedly use a zero day\u2014and perhaps a second patch bypass\u2014but they also deployed a custom implant. That isn\u2019t opportunistic.&#8221;&nbsp;<\/p>\n<p>Yet at the same time, the sheer number of exploited systems suggests more of an indiscriminate approach,&nbsp;Baines says.<\/p>\n<p><strong>Cisco Pwning&nbsp;Likely From a Single&nbsp;Threat Actor<\/strong><\/p>\n<p>The fact that the compromised Cisco IOS XE systems all have the same implant suggests that one threat actor is behind the attacks. &#8220;Because the initial auth-bypass vulnerability was\u2014and still is unpatched\u2014finding vulnerable targets is as simple as a Shodan query,&#8221; Baines adds. Because Cisco has not made details of the vulnerability public yet, it is to ascertain how easy or not CVE-2023-20198 is to exploit, he notes.<\/p>\n<p>Researchers at Detectify too on Tuesday reported observing what appears to be Internet-wide exploit activity targeted the Cisco zero-day vulnerability. But they believe the threat actor behind it is opportunistically hitting every affected system they can find. &#8220;The attackers seem to be casting a wide net by attempting to exploit systems without a specific target in mind first,&#8221; one researcher from the firm says. The approach appears to be to &#8220;exploit everything first and then determine what is interesting&#8221;. Detectify&#8217;s researchers shared Baines&#8217; assessment about affected systems being trivially easy to find via search engines like Shodan.<\/p>\n<p>Detectify&#8217;s team only verified a relatively limited number of systems as being infected while building a test for detecting the implant for customers, the researcher says. But it is conceivable that thousands of systems have the implant, the researcher adds.<\/p>\n<p><strong>Access Lists Are Effective Mitigation<\/strong><\/p>\n<p>Cisco has not yet released a patch for the zero-day threat. But the company has recommended that organizations with affected systems immediately disable the HTTPS Server feature on Internet-facing IOS XE devices. On Tuesday, Cisco <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z\" target=\"_blank\" rel=\"noopener\">updated its advisory<\/a> to note that controlling access to the HTTPS Server feature using access lists, works as well.<\/p>\n<p>&#8220;We assess with high confidence, based on further understanding of the exploit, that access lists applied to the HTTP Server feature to restrict access from untrusted hosts and networks are an effective mitigation,&#8221; Cisco said. When implementing access controls for these services, organization need to be cognizant of what they are doing because of the potential for interruption of production services, the company cautioned.<\/p>\n<p>Cisco did not respond to a Dark Reading question about the reports about thousands of systems having the implant via the new zero-day bug. But in an emailed statement the company said it is &#8220;working non-stop&#8221; to provide a software fix. In the meantime, customers should immediately implement the steps outlined in the security advisory, the statement reiterated.&nbsp;<\/p>\n<p> &#8220;Cisco has nothing more to share at this time but will provide an update on the status of our investigation through the security advisory. Please refer to the <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z\" target=\"_blank\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z&amp;source=gmail&amp;ust=1697651026777000&amp;usg=AOvVaw3DBaELshasiTgZ4O2fN4_v\" rel=\"noopener\">security advisory<\/a> and Talos <a href=\"https:\/\/blog.talosintelligence.com\/active-exploitation-of-cisco-ios-xe-software\" target=\"_blank\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/blog.talosintelligence.com\/active-exploitation-of-cisco-ios-xe-software&amp;source=gmail&amp;ust=1697651026778000&amp;usg=AOvVaw3S3GB0rdsdJuoLLPpOynFU\" rel=\"noopener\">blog<\/a> for additional details.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/ten-thousand-cisco-ios-xe-systems-compromised-zero-day-bug\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just a day after Cisco disclosed CVE-2023-20198, it remains unpatched, and one vendor says a Shodan scan shows at least 10,000 Cisco devices with an implant for arbitrary code execution on them. The vendor meanwhile has updated the advisory with more mitigation steps.Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/ten-thousand-cisco-ios-xe-systems-compromised-zero-day-bug\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-54165","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-17T19:11:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised\",\"datePublished\":\"2023-10-17T19:11:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/\"},\"wordCount\":815,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8c3c086eace2cd00\\\/652ec92360742fbd16c11a0e\\\/zeroday_znakki_shutterstock.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/\",\"name\":\"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8c3c086eace2cd00\\\/652ec92360742fbd16c11a0e\\\/zeroday_znakki_shutterstock.jpg\",\"datePublished\":\"2023-10-17T19:11:13+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8c3c086eace2cd00\\\/652ec92360742fbd16c11a0e\\\/zeroday_znakki_shutterstock.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8c3c086eace2cd00\\\/652ec92360742fbd16c11a0e\\\/zeroday_znakki_shutterstock.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/","og_locale":"en_US","og_type":"article","og_title":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-10-17T19:11:13+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised","datePublished":"2023-10-17T19:11:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/"},"wordCount":815,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/","url":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/","name":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg","datePublished":"2023-10-17T19:11:13+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8c3c086eace2cd00\/652ec92360742fbd16c11a0e\/zeroday_znakki_shutterstock.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-alert-ten-thousand-cisco-ios-xe-systems-now-compromised\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=54165"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54165\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=54165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=54165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=54165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}