logo

The Three-Year Shadow: Critical CVSS 10 Cisco SD-WAN Zero-Day Exploited by UAT-8616

ID: caa3642a-e48a-525c-bcf5-ae3e34dc360a

STIX ID: report--caa3642a-e48a-525c-bcf5-ae3e34dc360a

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-02-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos warns of active, ongoing exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN Controller that allows unauthenticated remote attackers to bypass authentication, gain high-privileged admin access, and manipulate NETCONF configuration; the activity is tracked as cluster UAT-8616, has been observed since 2023, includes a downgrade-to-exploit privilege escalation using CVE-2022-20775, and Cisco recommends applying fixed releases and restricting controller connectivity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.