Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting

Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) (TL-2026-0145), also tracked as cisco-sa-sdwan-rpa-EHchtZk, is a critical-severity zero-day vulnerability scored CVSS 10, first published 2026-02-26. It is attributed to UAT-8616 (China) with high confidence, affects Cisco Catalyst SD-WAN Controller (formerly vSmart), references 2 CVEs (CVE-2026-20127, CVE-2022-20775), maps to 19 MITRE ATT&CK techniques (T1021.004, T1039, T1040), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0145

Threat ID
TL-2026-0145
Also known as
cisco-sa-sdwan-rpa-EHchtZk, AL26-004, ED 26-03
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
ZERO_DAY
First published
2026-02-26
Last reviewed
2026-02-26
Attribution
UAT-8616
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
critical-infrastructure, government, telecommunications, healthcare, energy, financial
Target regions
Global, Australia, United Kingdom, Canada, North America
Detection rules
9
Indicators of compromise
15

CVE-2026-20127 is a critical (CVSS 10.0) unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and SD-WAN Manager (formerly vManage). Actively exploited since at least 2023 by UAT-8616, a highly sophisticated threat actor tracked by Cisco Talos. Exploitation grants administrative privileges via crafted peering requests, enabling NETCONF access to manipulate the entire SD-WAN fabric configuration. Post-exploitation chains with CVE-2022-20775 (path traversal) for root escalation via software version downgrade. Joint advisories from ACSC (Australia), NCSC (UK), CCCS (Canada), and CISA Emergency Directive 26-03.

How Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) works

CVE-2026-20127 is a critical authentication bypass vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. The vulnerability exists because the peering authentication mechanism is not working properly, allowing an unauthenticated remote attacker to send crafted requests to bypass authentication and obtain administrative privileges on the affected system.

Successful exploitation allows the attacker to log in as an internal, high-privileged, non-root user account. Using this account, the attacker gains access to NETCONF, which enables manipulation of network configuration across the entire SD-WAN fabric — a catastrophic compromise for organizations relying on SD-WAN for branch connectivity and network segmentation.

Cisco Talos tracks the exploitation activity as UAT-8616, assessed with high confidence to be a highly sophisticated cyber threat actor. Investigation revealed that malicious activity dates back at least three years to 2023, making this a long-running zero-day exploitation campaign. Investigation by intelligence partners (ACSC Australia) identified that UAT-8616 escalated to root via a version downgrade attack: the actor downgrades the SD-WAN software to a vulnerable version, exploits CVE-2022-20775 (CWE-25, path traversal via crafted username with '/../../' strings) for root privilege escalation, then restores the original software version to cover tracks.

The vulnerability affects all deployment types: On-Premises, Cisco Hosted SD-WAN Cloud, Cisco Hosted SD-WAN Cloud - Cisco Managed, and Cisco Hosted SD-WAN Cloud - FedRAMP Environment. Systems with internet-exposed management or control planes and exposed ports are at highest risk.

Post-compromise indicators include: unauthorized control connection peering events (especially vManage peer types from unknown IPs), creation and deletion of malicious user accounts with absent bash_history and cli-history, interactive root sessions with unauthorized SSH keys in /home/root/.ssh/authorized_keys (with PermitRootLogin set to yes), unauthorized SSH keys for vmanage-admin account, abnormally small or zero-byte log files (syslog, wtmp, lastlog, cli-history, bash_history), evidence of log clearing/truncation, unexplained peer additions/drops, and unauthorized version downgrade/upgrade cycles with system reboots.

The CISA added both CVE-2026-20127 and CVE-2022-20775 to the Known Exploited Vulnerabilities catalog on 2026-02-25, with a remediation due date of 2026-02-27 (2-day deadline reflecting emergency severity). CISA issued Emergency Directive 26-03. Multi-nation response: Cisco Talos (US), ACSC (Australia), NCSC (UK), CCCS (Canada) all issued coordinated advisories and hunt guides.

UAT-8616's targeting of SD-WAN controllers represents a critical escalation in the network edge device targeting trend. Compromising the SD-WAN controller gives an attacker the ability to reconfigure the entire overlay network, redirect traffic, intercept communications, and establish persistent access across all branch sites — far more impactful than compromising a single endpoint. Cisco released Snort rules 65938 and 65958 for detection.

MITRE ATT&CK techniques used in TL-2026-0145

lateral-movement

T1021.004 SSH

collection

T1039 Data from Network Shared Drive

credential-access

T1040 Network Sniffing; T1552.004 Private Keys; T1557 Adversary-in-the-Middle

discovery

T1046 Network Service Discovery; T1082 System Information Discovery

privilege-escalation

T1068 Exploitation for Privilege Escalation

defense-evasion

T1070.003 Clear Command History; T1078.001 Default Accounts

command-and-control

T1090.002 External Proxy; T1219 Remote Access Tools

persistence

T1098.004 SSH Authorized Keys; T1133 External Remote Services; T1136.001 Local Account

initial-access

T1190 Exploit Public-Facing Application

impact

T1498 Network Denial of Service

defense-impairment

T1685.006 Clear Linux or Mac System Logs; T1689 Downgrade Attack

Affected products and versions in Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

  • Cisco — Catalyst SD-WAN Controller (formerly vSmart)
    Vulnerable versions: < 20.9.8.2; 20.11; 20.12.x < 20.12.5.3; 20.13; 20.14; 20.15.x < 20.15.4.2; 20.16; 20.18.x < 20.18.2.1
    Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1
  • Cisco — Catalyst SD-WAN Manager (formerly vManage)
    Vulnerable versions: All versions prior to fixed releases
    Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1

Remediation for Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

Patches

  • Cisco Catalyst SD-WAN 20.9.8.2 (estimated 2026-02-27)
  • Cisco Catalyst SD-WAN 20.12.5.3
  • Cisco Catalyst SD-WAN 20.12.6.1
  • Cisco Catalyst SD-WAN 20.15.4.2
  • Cisco Catalyst SD-WAN 20.18.2.1

Immediate actions

  • Audit auth.log for 'Accepted publickey for vmanage-admin from' entries from unknown IPs
  • Validate all control connection peering events against known topology
  • Check for unauthorized SSH keys in /home/root/.ssh/authorized_keys and /home/vmanage-admin/.ssh/authorized_keys
  • Verify PermitRootLogin is not set to 'yes' in /etc/ssh/sshd_config
  • Check for zero-byte or abnormally small log files (syslog, wtmp, lastlog, cli-history, bash_history)
  • Restrict port 22 and port 830 via ACLs/firewall to known controller IPs only
  • Collect virtual snapshots and logs from all SD-WAN components before remediation

Workarounds

  • No workarounds available — mitigation only: restrict ports 22 and 830 to known controller IPs via ACLs

Longer-term hardening

  • Upgrade to fixed releases: 20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, or 20.18.2.1
  • Implement Cisco Catalyst SD-WAN hardening guide
  • Replace self-signed certificates on SD-WAN Manager web UI
  • Enable pairwise keying for control and data plane security
  • Forward all logs to remote syslog server (prevents local log tampering)
  • Set session timeout to shortest period possible
  • Isolate VPN 512 (management) interfaces behind firewall

CVEs associated with Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

CVE-2026-20127, CVE-2022-20775

Weaknesses (CWE) in Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

CWE-287, CWE-25

Timeline of Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

  • CVE-2022-20775 (SD-WAN CLI path traversal, CVSS 7.8) published by Cisco. Later chained by UAT-8616 for root escalation.
  • Earliest known UAT-8616 exploitation activity dating back at least three years (2023) as confirmed by Cisco Talos investigation.
  • Example IOC timestamp from Cisco advisory: unauthorized SSH publickey acceptance for vmanage-admin from unknown IP.
  • Cisco releases fixed versions: 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1. Version 20.9.8.2 estimated for 2026-02-27.
  • Joint advisories published: ACSC (Australia) hunt guide, NCSC (UK) exploitation alert, CCCS (Canada) AL26-004, CISA ED 26-03.
  • Coordinated disclosure: Cisco Talos blog, Cisco Security Advisory (cisco-sa-sdwan-rpa-EHchtZk), CISA KEV addition, CISA Emergency Directive 26-03.
  • CISA KEV remediation deadline — 2-day turnaround reflecting emergency severity of active zero-day exploitation.
  • As of 2026-05-29, CVE-2026-20127 is fully patched and remains in CISA KEV (ED 26-03), but per Talos/Tenable (May 14-15, 2026) actor UAT-8616 stays operational, having escalated to the new CVE-2026-20182 plus ~10 clusters exploiting related CVEs. This specific CVE is remediated/superseded by newer SD-WAN zero-days, yet the campaign and actor are active.

Sources cited for Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

Threats related to Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)

Detection coverage for TL-2026-0145

As of 2026-02-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0145 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats