Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting
Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) (TL-2026-0145), also tracked as cisco-sa-sdwan-rpa-EHchtZk, is a critical-severity zero-day vulnerability scored CVSS 10, first published 2026-02-26. It is attributed to UAT-8616 (China) with high confidence, affects Cisco Catalyst SD-WAN Controller (formerly vSmart), references 2 CVEs (CVE-2026-20127, CVE-2022-20775), maps to 19 MITRE ATT&CK techniques (T1021.004, T1039, T1040), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0145
- Threat ID
- TL-2026-0145
- Also known as
- cisco-sa-sdwan-rpa-EHchtZk, AL26-004, ED 26-03
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- ZERO_DAY
- First published
- 2026-02-26
- Last reviewed
- 2026-02-26
- Attribution
- UAT-8616
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- critical-infrastructure, government, telecommunications, healthcare, energy, financial
- Target regions
- Global, Australia, United Kingdom, Canada, North America
- Detection rules
- 9
- Indicators of compromise
- 15
CVE-2026-20127 is a critical (CVSS 10.0) unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and SD-WAN Manager (formerly vManage). Actively exploited since at least 2023 by UAT-8616, a highly sophisticated threat actor tracked by Cisco Talos. Exploitation grants administrative privileges via crafted peering requests, enabling NETCONF access to manipulate the entire SD-WAN fabric configuration. Post-exploitation chains with CVE-2022-20775 (path traversal) for root escalation via software version downgrade. Joint advisories from ACSC (Australia), NCSC (UK), CCCS (Canada), and CISA Emergency Directive 26-03.
How Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) works
CVE-2026-20127 is a critical authentication bypass vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. The vulnerability exists because the peering authentication mechanism is not working properly, allowing an unauthenticated remote attacker to send crafted requests to bypass authentication and obtain administrative privileges on the affected system.
Successful exploitation allows the attacker to log in as an internal, high-privileged, non-root user account. Using this account, the attacker gains access to NETCONF, which enables manipulation of network configuration across the entire SD-WAN fabric — a catastrophic compromise for organizations relying on SD-WAN for branch connectivity and network segmentation.
Cisco Talos tracks the exploitation activity as UAT-8616, assessed with high confidence to be a highly sophisticated cyber threat actor. Investigation revealed that malicious activity dates back at least three years to 2023, making this a long-running zero-day exploitation campaign. Investigation by intelligence partners (ACSC Australia) identified that UAT-8616 escalated to root via a version downgrade attack: the actor downgrades the SD-WAN software to a vulnerable version, exploits CVE-2022-20775 (CWE-25, path traversal via crafted username with '/../../' strings) for root privilege escalation, then restores the original software version to cover tracks.
The vulnerability affects all deployment types: On-Premises, Cisco Hosted SD-WAN Cloud, Cisco Hosted SD-WAN Cloud - Cisco Managed, and Cisco Hosted SD-WAN Cloud - FedRAMP Environment. Systems with internet-exposed management or control planes and exposed ports are at highest risk.
Post-compromise indicators include: unauthorized control connection peering events (especially vManage peer types from unknown IPs), creation and deletion of malicious user accounts with absent bash_history and cli-history, interactive root sessions with unauthorized SSH keys in /home/root/.ssh/authorized_keys (with PermitRootLogin set to yes), unauthorized SSH keys for vmanage-admin account, abnormally small or zero-byte log files (syslog, wtmp, lastlog, cli-history, bash_history), evidence of log clearing/truncation, unexplained peer additions/drops, and unauthorized version downgrade/upgrade cycles with system reboots.
The CISA added both CVE-2026-20127 and CVE-2022-20775 to the Known Exploited Vulnerabilities catalog on 2026-02-25, with a remediation due date of 2026-02-27 (2-day deadline reflecting emergency severity). CISA issued Emergency Directive 26-03. Multi-nation response: Cisco Talos (US), ACSC (Australia), NCSC (UK), CCCS (Canada) all issued coordinated advisories and hunt guides.
UAT-8616's targeting of SD-WAN controllers represents a critical escalation in the network edge device targeting trend. Compromising the SD-WAN controller gives an attacker the ability to reconfigure the entire overlay network, redirect traffic, intercept communications, and establish persistent access across all branch sites — far more impactful than compromising a single endpoint. Cisco released Snort rules 65938 and 65958 for detection.
MITRE ATT&CK techniques used in TL-2026-0145
lateral-movement
collection
T1039 Data from Network Shared Drive
credential-access
T1040 Network Sniffing; T1552.004 Private Keys; T1557 Adversary-in-the-Middle
discovery
T1046 Network Service Discovery; T1082 System Information Discovery
privilege-escalation
T1068 Exploitation for Privilege Escalation
defense-evasion
T1070.003 Clear Command History; T1078.001 Default Accounts
command-and-control
T1090.002 External Proxy; T1219 Remote Access Tools
persistence
T1098.004 SSH Authorized Keys; T1133 External Remote Services; T1136.001 Local Account
initial-access
T1190 Exploit Public-Facing Application
impact
T1498 Network Denial of Service
defense-impairment
T1685.006 Clear Linux or Mac System Logs; T1689 Downgrade Attack
Affected products and versions in Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
- Cisco — Catalyst SD-WAN Controller (formerly vSmart)
Vulnerable versions: < 20.9.8.2; 20.11; 20.12.x < 20.12.5.3; 20.13; 20.14; 20.15.x < 20.15.4.2; 20.16; 20.18.x < 20.18.2.1
Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1 - Cisco — Catalyst SD-WAN Manager (formerly vManage)
Vulnerable versions: All versions prior to fixed releases
Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1
Remediation for Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
Patches
- Cisco Catalyst SD-WAN 20.9.8.2 (estimated 2026-02-27)
- Cisco Catalyst SD-WAN 20.12.5.3
- Cisco Catalyst SD-WAN 20.12.6.1
- Cisco Catalyst SD-WAN 20.15.4.2
- Cisco Catalyst SD-WAN 20.18.2.1
Immediate actions
- Audit auth.log for 'Accepted publickey for vmanage-admin from' entries from unknown IPs
- Validate all control connection peering events against known topology
- Check for unauthorized SSH keys in /home/root/.ssh/authorized_keys and /home/vmanage-admin/.ssh/authorized_keys
- Verify PermitRootLogin is not set to 'yes' in /etc/ssh/sshd_config
- Check for zero-byte or abnormally small log files (syslog, wtmp, lastlog, cli-history, bash_history)
- Restrict port 22 and port 830 via ACLs/firewall to known controller IPs only
- Collect virtual snapshots and logs from all SD-WAN components before remediation
Workarounds
- No workarounds available — mitigation only: restrict ports 22 and 830 to known controller IPs via ACLs
Longer-term hardening
- Upgrade to fixed releases: 20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, or 20.18.2.1
- Implement Cisco Catalyst SD-WAN hardening guide
- Replace self-signed certificates on SD-WAN Manager web UI
- Enable pairwise keying for control and data plane security
- Forward all logs to remote syslog server (prevents local log tampering)
- Set session timeout to shortest period possible
- Isolate VPN 512 (management) interfaces behind firewall
CVEs associated with Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
Weaknesses (CWE) in Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
CWE-287, CWE-25
Timeline of Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
- CVE-2022-20775 (SD-WAN CLI path traversal, CVSS 7.8) published by Cisco. Later chained by UAT-8616 for root escalation.
- Earliest known UAT-8616 exploitation activity dating back at least three years (2023) as confirmed by Cisco Talos investigation.
- Example IOC timestamp from Cisco advisory: unauthorized SSH publickey acceptance for vmanage-admin from unknown IP.
- Cisco releases fixed versions: 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1. Version 20.9.8.2 estimated for 2026-02-27.
- Joint advisories published: ACSC (Australia) hunt guide, NCSC (UK) exploitation alert, CCCS (Canada) AL26-004, CISA ED 26-03.
- Coordinated disclosure: Cisco Talos blog, Cisco Security Advisory (cisco-sa-sdwan-rpa-EHchtZk), CISA KEV addition, CISA Emergency Directive 26-03.
- CISA KEV remediation deadline — 2-day turnaround reflecting emergency severity of active zero-day exploitation.
- As of 2026-05-29, CVE-2026-20127 is fully patched and remains in CISA KEV (ED 26-03), but per Talos/Tenable (May 14-15, 2026) actor UAT-8616 stays operational, having escalated to the new CVE-2026-20182 plus ~10 clusters exploiting related CVEs. This specific CVE is remediated/superseded by newer SD-WAN zero-days, yet the campaign and actor are active.
Sources cited for Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
- Cisco Talos: Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
- Cisco Security Advisory: CVE-2026-20127 — Authentication Bypass Vulnerability
- ACSC: Cisco Catalyst SD-WAN Hunt Guide
- NCSC (UK): Exploitation of Cisco Catalyst SD-WANs
- CCCS (Canada): AL26-004 — Critical vulnerability affecting Cisco Catalyst SD-WAN
- NVD: CVE-2026-20127 — CVSS 10.0 Authentication Bypass
- NVD: CVE-2022-20775 — SD-WAN CLI Path Traversal (chained for root)
- CISA KEV: CVE-2026-20127 — Emergency Directive 26-03
- Cisco Catalyst SD-WAN Hardening Guide
Threats related to Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127)
- CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation
- CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0)
- Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)
Detection coverage for TL-2026-0145
As of 2026-02-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0145 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.