logo

PoC Exploit for Cisco SD-WAN 0-Day Vulnerability Now Released, Actively Exploited in the Wild

ID: 7d6b4f7a-0143-531d-98af-4d6e4a7daacf

STIX ID: report--7d6b4f7a-0143-531d-98af-4d6e4a7daacf

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Divya

...
...

A critical zero-day (CVE-2026-20127) in Cisco Catalyst SD-WAN is being actively exploited by an advanced actor (UAT-8616); attackers can bypass authentication to gain administrative access, downgrade software to exploit an older vulnerability (CVE-2022-20775) for root, and restore versions to hide activity. A public PoC (with web shells) increases exploitation risk, and defenders are urged to apply Cisco hardening guidance, hunt for IOCs (malicious accounts, unexpected peering, unauthorized SSH keys, log tampering), and monitor for unauthorized version downgrades.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.