Governments issue warning over Cisco zero-day attacks dating back to 2023
ID: ba87c85c-1866-5601-80c5-3cd9c53bfebc
STIX ID: report--ba87c85c-1866-5601-80c5-3cd9c53bfebc
Feed Name: CyberScoop
Attackers have been exploiting two zero-day vulnerabilities in Cisco SD-WAN (CVE-2026-20127 and CVE-2022-20775) in a global campaign that persisted for at least three years; the chain involves an authentication bypass via CVE-2026-20127 followed by downgrading software to exploit CVE-2022-20775 to escalate to root. CISA issued an emergency directive and the Five Eyes published hunt and hardening guidance; Cisco Talos attributes the activity to a sophisticated cluster labeled UAT-8616 and recommends patching, rebuilding affected systems, and hunting for evidence of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
