Hackers abused Cisco SD-WAN zero-day since 2023 to gain full admin control
ID: 7701fc1b-eb25-5e0b-9084-76b6b69fbdb0
STIX ID: report--7701fc1b-eb25-5e0b-9084-76b6b69fbdb0
Feed Name: Security Affairs
A critical, actively exploited zero-day (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN Controllers has been abused since 2023 to bypass authentication and obtain full administrative access, enabling attackers to access NETCONF and manipulate network configurations; Cisco Talos attributes the campaign to a highly sophisticated actor tracked as UAT-8616, who also used a software downgrade and CVE-2022-20775 to escalate to root. Cisco and partners urge immediate patching to fixed releases, network hardening, hunting for suspicious 'Accepted publickey for vmanage-admin' log entries, and engaging TAC if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
