PoC Exploit for Cisco SD-WAN 0-Day Vulnerability Now Released, Actively Exploited in the Wild
ID: 7d6b4f7a-0143-531d-98af-4d6e4a7daacf
STIX ID: report--7d6b4f7a-0143-531d-98af-4d6e4a7daacf
Feed Name: GBHackers
A critical zero-day (CVE-2026-20127) in Cisco Catalyst SD-WAN is being actively exploited by an advanced actor (UAT-8616); attackers can bypass authentication to gain administrative access, downgrade software to exploit an older vulnerability (CVE-2022-20775) for root, and restore versions to hide activity. A public PoC (with web shells) increases exploitation risk, and defenders are urged to apply Cisco hardening guidance, hunt for IOCs (malicious accounts, unexpected peering, unauthorized SSH keys, log tampering), and monitor for unauthorized version downgrades.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
