Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
ID: 33aaeade-1c1e-5dea-a1ce-089257ec3ec9
STIX ID: report--33aaeade-1c1e-5dea-a1ce-089257ec3ec9
Feed Name: The Register (Security)
Threat Score
Five Eyes intelligence agencies warn that attackers are actively exploiting two Cisco Catalyst SD-WAN flaws—CVE-2026-20127 (improper authentication, CVSS 10.0) and CVE-2022-20775 (path traversal, CVSS 7.8)—to obtain admin and root access, reconfigure NETCONF, add rogue peers and maintain persistence; Cisco Talos attributes the activity to group UAT-8616 and advises immediate hunting and patching, particularly for organisations in critical and high-value sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
