The Three-Year Shadow: Critical CVSS 10 Cisco SD-WAN Zero-Day Exploited by UAT-8616
ID: caa3642a-e48a-525c-bcf5-ae3e34dc360a
STIX ID: report--caa3642a-e48a-525c-bcf5-ae3e34dc360a
Feed Name: securityonline.info
Cisco Talos warns of active, ongoing exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN Controller that allows unauthenticated remote attackers to bypass authentication, gain high-privileged admin access, and manipulate NETCONF configuration; the activity is tracked as cluster UAT-8616, has been observed since 2023, includes a downgrade-to-exploit privilege escalation using CVE-2022-20775, and Cisco recommends applying fixed releases and restricting controller connectivity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
