logo

Weaponized in the Wild: Public PoC Exploit Disclosed for Critical 10.0 Cisco SD-WAN Flaw

ID: 58710cac-099c-5aaf-b3d9-02d457f32c5b

STIX ID: report--58710cac-099c-5aaf-b3d9-02d457f32c5b

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical authentication bypass in Cisco Catalyst SD-WAN (CVE-2026-20127, CVSS 10.0) has been exploited by the sophisticated actor UAT-8616 since at least 2023; the actor implanted a rogue peer, downgraded software to exploit CVE-2022-20775 for root access, then restored versions and erased logs to maintain stealth. The public release of a proof-of-concept exploit increases risk of widespread attacks, prompting CISA Emergency Directive 26-03 and Cisco patch releases (20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1); organizations are advised to collect forensic artifacts and apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.