THE INFRASTRUCTURE DEFENDER
Cyber Threat Intelligence Summary
April 13, 2026 | Auth ID: one-IMPRIMIS
Source: Imprimis, Inc. | CyberDeck Blog

Reporting Period: March 1, 2026 – April 13, 2026
(Focus on new disclosures since last Sunday, April 5)
Executive Summary
The security landscape for early April 2026 is dominated by urgent remediation requirements for critical infrastructure and enterprise management platforms. The most severe threat remains the Cisco Catalyst SD-WAN authentication bypass, which is subject to a federal emergency directive. Additionally, a high-severity zero-day in Qualcomm chipsets is seeing active, targeted exploitation. Organizations should also prioritize patching VMware Aria Operations following confirmed exploitation in the wild.
Top Risks This Period
Cisco Catalyst SD-WAN (Active Exploitation): A critical authentication bypass (CVE-2026-20127, CVSS 10.0) is being actively exploited by threat actor UAT-8616. Attackers can gain unauthenticated administrative access to the SD-WAN management plane.
Qualcomm Android Zero-Day: CVE-2026-21385 is a high-severity memory corruption flaw in display components affecting 234 chipsets. It is currently under "limited, targeted exploitation."
VMware Aria Operations: CVE-2026-22719, a command injection vulnerability (CVSS 8.1), has been added to the CISA KEV catalog. It allows unauthenticated root access during support-assisted migration.
Remediate Cisco SD-WAN: Per CISA Emergency Directive 26-03, organizations must inventory all Catalyst SD-WAN systems and apply patches. Hunt for "root" login anomalies and unexpected reboot events.
Patch VMware Aria Operations: Apply the update to version 8.18.6 or VCF 9.0.2.0 immediately. CISA added this to the KEV catalog on March 3, 2026, with an immediate remediation timeline for affected environments.
Update Android Fleet: Ensure all Android devices have a security patch level of March 5, 2026, or later to mitigate the exploited Qualcomm zero-day.
Microsoft Devices Pricing Program (CVE-2026-21536): A Critical (CVSS 9.8) remote code execution vulnerability. Public PoC code is available on GitHub. This affects all versions and allows unauthenticated RCE via unrestricted file upload.
Microsoft ACI Confidential Containers: Three critical vulnerabilities (CVE-2026-26122, CVE-2026-26124, CVE-2026-23651) were addressed. These could allow attackers to escape access boundaries or disclose sensitive information.
Payment Orchestrator Service (CVE-2026-26125): A critical elevation of privilege (CVSS 8.6) allows remote attackers with no privileges to gain elevated access.
Microsoft Edge: Routine security updates for the 145.x branch were released to address minor vulnerabilities and align with Chromium security baselines.
Microsoft Office: Critical RCE vulnerabilities (CVE-2026-26110, CVE-2026-26113) were patched in the March update. A zero-click information disclosure flaw in Excel was also noted as potentially affecting Copilot Agent mode.
Google Meet Audit Logs: Enhanced logging now includes the "permission type" used to join meetings, aiding in unauthorized access investigations.
LexisNexis Breach Context: A confirmed breach in March involved the React2Shell exploit and over-permissive AWS ECS task roles. This underscores the need for "Least Privilege" auditing for cloud secrets management.
|
Title |
Product |
Severity |
Exploited |
CVE / ID |
Fixed Version |
|
SD-WAN Auth Bypass |
Cisco Catalyst SD-WAN |
10.0 (Crit) |
Yes |
CVE-2026-20127 |
Per Vendor Guide |
|
Aria Command Injection |
VMware Aria Operations |
8.1 (High) |
Yes |
CVE-2026-22719 |
8.18.6 / VCF 9.0.2 |
|
Qualcomm Display Flaw |
Android / Qualcomm |
7.8 (High) |
Yes |
CVE-2026-21385 |
March 5, 2026 Patch |
|
Devices Pricing RCE |
Microsoft Devices Pricing |
9.8 (Crit) |
No (PoC avail) |
CVE-2026-21536 |
March 2026 Update |
|
ACI Escape |
ACI Confidential Containers |
6.7 (Crit) |
No |
CVE-2026-26124 |
March 2026 Update |
CISA Known Exploited Vulnerabilities (KEV) Catalog (Updated March/April 2026).
CISA Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems.
Microsoft Security Response Center (MSRC) - March/April 2026 Update Guide.
CrowdStrike Patch Tuesday Analysis (March 2026).
Qualcomm Security Bulletin (March 2026).
Broadcom (VMware) Security Advisory VMSA-2026-0005.