Hackers Exploited Cisco SD-WAN Zero-Day for Three Years Before Detection
ID: ab7cd491-6b81-59c9-a82b-46d625c4d68c
STIX ID: report--ab7cd491-6b81-59c9-a82b-46d625c4d68c
Feed Name: The Cyber Express
Cisco Talos reports a sophisticated threat actor (UAT-8616) actively exploited a critical authentication-bypass zero-day (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN controllers for at least three years to gain administrative access, then escalated to root by downgrading software to exploit CVE-2022-20775 before restoring versions to hide activity; CISA, ACSC and NCSC issued urgent guidance and CISA released an emergency directive while Cisco published patches and remediation guidance. Indicators include creation and deletion of malicious accounts, missing shell histories, unexpected SD-WAN peering events, unauthorized SSH keys, and log truncation; organisations are advised to apply patches, harden management interfaces, implement external logging, and hunt for the provided IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
