logo

Hackers abused Cisco SD-WAN zero-day since 2023 to gain full admin control

ID: 7701fc1b-eb25-5e0b-9084-76b6b69fbdb0

STIX ID: report--7701fc1b-eb25-5e0b-9084-76b6b69fbdb0

Feed Name: Security Affairs

Threat Score
95/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical, actively exploited zero-day (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN Controllers has been abused since 2023 to bypass authentication and obtain full administrative access, enabling attackers to access NETCONF and manipulate network configurations; Cisco Talos attributes the campaign to a highly sophisticated actor tracked as UAT-8616, who also used a software downgrade and CVE-2022-20775 to escalate to root. Cisco and partners urge immediate patching to fixed releases, network hardening, hunting for suspicious 'Accepted publickey for vmanage-admin' log entries, and engaging TAC if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.