logo

Cisco SD-WAN Zero-Day Under Exploitation for 3 Years

ID: 84db640a-6773-525d-b13b-340484cb3069

STIX ID: report--84db640a-6773-525d-b13b-340484cb3069

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Cisco disclosed a critical CVE-2026-20127 authentication-bypass zero-day in Catalyst SD-WAN Controllers that has been exploited in the wild since at least 2023 by a highly sophisticated actor tracked as UAT-8616; the actor added rogue peers, downgraded controllers to exploit CVE-2022-20775 for root escalation, and created persistent accounts. CISA issued an emergency directive to federal agencies to patch immediately, and intelligence partners published a 41-page hunt guide with mitigation steps including patching to fixed versions, disabling HTTP admin access, restricting Internet exposure, and hunting for rogue peering, downgrades, and unexpected reboots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.