Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
ID: 8d371a2b-2aa1-5b01-819b-0bf5365a78e8
STIX ID: report--8d371a2b-2aa1-5b01-819b-0bf5365a78e8
Feed Name: Cisco Talos
Threat Score
Cisco Talos reports active exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN Controller by a highly sophisticated actor dubbed UAT-8616, with evidence of persistent access since 2023 including root escalation via version downgrade and follow-on exploitation of CVE-2022-20775; the advisory includes hunting guidance, sample log indicators, IOC types (unauthorized peers, SSH key artifacts, log tampering), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
