Monitoring active sources

Intelligence Beyond
the Surface.

Before the Headlines.

Structured breach and exploit intelligence for regulated sectors — sourced from public disclosures, scored by evidence depth, delivered before mainstream reporting catches up.

This is the product.

Each issue contains structured threat cards — standardized, evidence-based, sector-tagged. No noise. No hype. Just structured signal.

FS-2026-0041 KEV Listed
Energy / OT Healthcare
Cisco Catalyst SD-WAN Manager Authentication Bypass
Threat Type
Authentication Bypass
Severity
● Critical
Source Depth
KEV-Confirmed
First Observed
2026-02-25
Source Ecosystem
Authoritative + Vendor
Status
Active Exploitation
Operational Context

Allows unauthenticated remote access to SD-WAN Controller/Manager administrative interfaces via crafted requests that bypass peering authentication. CISA issued Emergency Directive ED 26-03 on Feb 25, 2026, requiring federal agencies to inventory all SD-WAN systems and apply fixes within 24 hours. In utility and healthcare environments where SD-WAN connects distributed OT infrastructure, compromise enables NETCONF access and manipulation of network configuration across the entire WAN fabric. Attackers are chaining this with CVE-2022-20775 for privilege escalation and long-term persistence.

How it works.

Three layers. Public sources in, structured intelligence out.

01
Source Aggregation

Continuous monitoring of CISA KEV, NVD, vendor security advisories, GitHub exploit commits, and public disclosure channels.

02
Structured Analysis

Raw signals are normalized, deduplicated, and structured into standardized threat objects with evidence-based source depth classification.

03
Sector Intelligence

Each threat is tagged by sector relevance and operational context — so energy, healthcare, and compliance teams see what matters to them.

Defensible collection. Public sources only.

No closed forums. No legal ambiguity. Every signal traces back to a verifiable public source.

CISA KEV Catalog NVD / CVE Feeds Vendor Security Advisories GitHub Security Commits Public Disclosure Channels Security Mailing Lists RSS Breach Feeds

Get the signal first.

FractalScript is in limited beta. Structured threat briefs delivered to your inbox — focused on regulated sectors, sourced transparently, formatted for action.