logo

Attackers Have Been Exploiting Cisco SD-WAN Zero-Day Flaw Since 2023

ID: 1f6d243f-3d41-5234-8c23-ca76b617d23c

STIX ID: report--1f6d243f-3d41-5234-8c23-ca76b617d23c

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Cisco Talos and Five Eyes agencies warn that threat actor UAT-8616 has been exploiting a zero-day in Cisco Catalyst SD-WAN Controller (CVE-2026-20127), chaining it with CVE-2022-20775 via a downgrade-then-restore privilege escalation to obtain root and manipulate the SD-WAN fabric (including NETCONF operations); agencies direct urgent inventory and patching, and an ACSC-led Hunt Guide provides detection, remediation, and notes on the actor’s persistence and anti-forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.