Active Exploitation of Cisco SD‑WAN Controller by UAT‑8616
🔒 Cisco Talos reports active exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN Controller, enabling unauthenticated attackers to bypass authentication and obtain administrative privileges. Talos attributes the activity to a sophisticated actor tracked as UAT-8616 and finds evidence dating to 2023, including software downgrades and subsequent exploitation of CVE-2022-20775 to escalate to root. Customers are urged to follow vendor advisories, validate control peering events, and apply the detection and remediation guidance provided.
