5 Nations Alert: Critical Cisco Bug Used in Global Espionage Campaign
ID: b7d8dba2-8829-56b9-a451-7f32741086a7
STIX ID: report--b7d8dba2-8829-56b9-a451-7f32741086a7
Feed Name: TechRepublic Security
A critical, actively-exploited vulnerability (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN appliances was used since 2023 to bypass authentication and gain privileged access; attackers then downgraded controllers to exploit CVE-2022-20775 to obtain root, create persistent accounts, and clear logs. The activity, attributed to an unidentified actor labeled UAT-8616, prompted joint advisories from Five Eyes nations and vendor reports; organizations are urged to preserve controller logs off-device, place controllers behind firewalls, and follow detection/mitigation guidance from Cisco and government agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
