logo

5 Nations Alert: Critical Cisco Bug Used in Global Espionage Campaign

ID: b7d8dba2-8829-56b9-a451-7f32741086a7

STIX ID: report--b7d8dba2-8829-56b9-a451-7f32741086a7

Feed Name: TechRepublic Security

Threat Score
90/100

Date Published: 2026-02-27

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

A critical, actively-exploited vulnerability (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN appliances was used since 2023 to bypass authentication and gain privileged access; attackers then downgraded controllers to exploit CVE-2022-20775 to obtain root, create persistent accounts, and clear logs. The activity, attributed to an unidentified actor labeled UAT-8616, prompted joint advisories from Five Eyes nations and vendor reports; organizations are urged to preserve controller logs off-device, place controllers behind firewalls, and follow detection/mitigation guidance from Cisco and government agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.