Weaponized in the Wild: Public PoC Exploit Disclosed for Critical 10.0 Cisco SD-WAN Flaw
ID: 58710cac-099c-5aaf-b3d9-02d457f32c5b
STIX ID: report--58710cac-099c-5aaf-b3d9-02d457f32c5b
Feed Name: securityonline.info
A critical authentication bypass in Cisco Catalyst SD-WAN (CVE-2026-20127, CVSS 10.0) has been exploited by the sophisticated actor UAT-8616 since at least 2023; the actor implanted a rogue peer, downgraded software to exploit CVE-2022-20775 for root access, then restored versions and erased logs to maintain stealth. The public release of a proof-of-concept exploit increases risk of widespread attacks, prompting CISA Emergency Directive 26-03 and Cisco patch releases (20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1); organizations are advised to collect forensic artifacts and apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
