Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogperimeter-device-exposurewidely-deployed-product-advisory

Active Exploitation of Cisco Catalyst SD-WAN Manager Vulnerabilities by UAT-8616

Updated 2mo agoFirst seen Mar 13, 20265 sources

CISA ordered U.S. federal civilian agencies to urgently remediate a critical Cisco Catalyst SD-WAN Manager compromise tied to CVE-2026-20127, a CVSS 10.0 authentication bypass flaw that allows attackers to obtain high-privilege access without valid credentials. Reporting indicates the activity was uncovered by CISA and Cisco Talos, which attributed exploitation to UAT-8616 and assessed that the intrusions date back to 2023. Attackers reportedly maintained persistence by downgrading devices to older vulnerable software and then using the access to reach NETCONF and manipulate SD-WAN fabric configuration, creating significant risk for federal networks and other exposed deployments.

Additional research shows the campaign is not limited to a single bug. Cisco disclosed in-the-wild exploitation of CVE-2026-20127 together with CVE-2022-20775, an older SD-WAN CLI flaw enabling post-auth privilege escalation and root command execution, while external analysis warned that public proof-of-concept material around CVE-2026-20127 has been misattributed and may produce incomplete detections. Researchers also highlighted broader exposure across internet-facing SD-WAN Manager instances and warned that CVE-2026-20133 may present underappreciated risk and could already be seeing exploitation, underscoring that defenders should treat the Cisco SD-WAN issue as an active intrusion and hardening priority rather than a routine patch cycle.

Share:
Active Exploitation of Cisco Catalyst SD-WAN Manager Vulnerabilities by UAT-8616
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
May 1, 20262mo ago

Final federal status report on Cisco SD-WAN response is due

A final status report on agency remediation and response actions for the Cisco SD-WAN incident is due to the Secretary of Homeland Security on May 1, 2026. This marks the last deadline referenced in the emergency response timeline.

Mar 23, 20263mo ago

Federal agencies must submit Cisco SD-WAN traffic logs to CISA

CISA required agencies to submit internal traffic logs and related remediation status for affected Cisco SD-WAN environments by March 23, 2026. The deadline was intended to support government-wide threat hunting and scope determination.

Mar 12, 20263mo ago

VulnCheck warns CVE-2026-20133 poses deeper compromise risk

On March 12, 2026, VulnCheck reported that community focus on CVE-2026-20127 had obscured the risk from CVE-2026-20133. The researchers said the flaw could expose sensitive files and secrets, facilitate NETCONF compromise, and support privilege escalation and broader SD-WAN compromise paths.

Cisco Talos and partners detail long-running UAT-8616 exploitation

By mid-March 2026, Cisco Talos reported that threat actor UAT-8616 had exploited CVE-2026-20127 and CVE-2022-20775 in the wild, with activity traced back to 2023. The Australian Signals Directorate, with Five Eyes partners, also published a hunting and tradecraft report on the campaign.

Mar 11, 20263mo ago

CISA issues second directive requiring hardening and rebuilds

On March 11, 2026, CISA followed up with a second emergency directive mandating additional hardening steps, key replacement, and full system rebuilds where root access may have been obtained. Agencies were also told to collect forensic artifacts, enable external log storage, and investigate for compromise.

Rapid7 publishes working exploit for CVE-2026-20127

A Rapid7 researcher released a working public exploit for CVE-2026-20127 on March 11, 2026. Researchers warned that the availability of a valid PoC could increase real-world exploitation attempts.

Cisco updates advisory to mark more SD-WAN flaws as exploited

After its initial February disclosures, Cisco updated its aggregate SD-WAN advisory to state that CVE-2026-20122 and CVE-2026-20128 were also being actively exploited. This expanded the set of known in-the-wild SD-WAN vulnerabilities beyond CVE-2026-20127.

Mar 3, 20264mo ago

Misattributed public PoC for CVE-2026-20127 is released

On March 3, 2026, a public exploit labeled as a PoC for CVE-2026-20127 was released by zerozenxlabs. VulnCheck later determined it did not exploit CVE-2026-20127, but instead chained CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 to obtain credentials and upload a webshell.

Feb 27, 20264mo ago

Federal agencies face initial Cisco SD-WAN patch deadline

CISA's first directive required U.S. federal agencies to complete initial software updates for affected Cisco SD-WAN systems by February 27, 2026. This marked the first mandatory remediation deadline in the government's response.

Feb 25, 20264mo ago

CISA issues first emergency directive for Cisco SD-WAN flaw

On February 25, 2026, CISA issued an emergency directive after discovering exploitation of Cisco Catalyst SD-WAN vulnerabilities in federal networks. The directive required agencies to begin urgent remediation of affected systems.

Cisco discloses six Catalyst SD-WAN Manager vulnerabilities

Cisco disclosed six vulnerabilities affecting Catalyst SD-WAN Manager on February 25, 2026, including the critical authentication bypass flaw CVE-2026-20127. The disclosures also covered additional SD-WAN Manager issues later tracked in Cisco's aggregate advisory.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.