Activity timeline
UAT-8616 appears in 6 tracked threats between and ; the busiest month was 2026-03 with 2 reports.
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 6 of 6 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 5 of 6 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 4 of 6 tracked threats
- T1078 Valid Accounts — Privilege Escalationobserved in 4 of 6 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 4 of 6 tracked threats
- T1498 Network Denial of Service — Impactobserved in 4 of 6 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 4 of 6 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 6 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
- T1090 Proxy — Command and Controlobserved in 3 of 6 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 3 of 6 tracked threats
- T1505 Server Software Component — Persistenceobserved in 3 of 6 tracked threats
- T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 3 of 6 tracked threats
- T1685.006 Clear Linux or Mac System Logs — Defense Impairmentobserved in 3 of 6 tracked threats
- T1021.004 SSH — Lateral Movementobserved in 2 of 6 tracked threats
Tracked threats
- Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)CRITICAL
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command Injection to RootHIGH
- Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by UAT-8616 (CVSS 10.0, CISA KEV, ED 26-03)CRITICAL
- CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0)CRITICAL
- CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active ExploitationCRITICAL
- Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure TargetingCRITICAL