PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild
ID: 39975379-5ad3-5839-91e3-6d5b122ecd0d
STIX ID: report--39975379-5ad3-5839-91e3-6d5b122ecd0d
Feed Name: cybersecurityNews.com
A public proof-of-concept exploit for CVE-2026-20127 — a critical pre-auth RCE in Cisco Catalyst SD-WAN — has been released (includes Python exploit, JSP webshell and deployable WAR) after active exploitation by the cluster UAT-8616 since at least 2023; the report describes how attackers bypass peering authentication to gain admin access, downgrade software to exploit an older vulnerability for root, restore versions to hide evidence, establish persistence (unauthorized SSH keys, webshell), perform lateral movement across SD-WAN appliances, and clear forensic logs. The advisory urges immediate patching (CISA KEV entry noted), auditing of SD-WAN peering and control-plane logs for rogue peer additions/SSH key changes/version downgrade cycles, and following threat-hunting guidance to detect compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
