Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting — Threadlinqs Intelligence
As of 2026-05-30, Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting is a critical-severity zero day threat attributed to UAT-8616 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0145 · Severity: CRITICAL · CVSS: 10 · Status: PATCHED · Category: ZERO_DAY
Attribution: UAT-8616 · China · ESPIONAGE
CVE-2026-20127 is a critical (CVSS 10.0) unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and SD-WAN Manager (formerly vManage).
CVE-2026-20127 is a critical authentication bypass vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. The vulnerability exists because the peering authentication mechanism is not working properly, allowing an unauthenticated remote attacker to send crafted requests to bypass authentication and obtain administrative privileges on the affected system.
Successful exploitation allows the attacker to log in as an internal, high-privileged, non-root user account. Using this account, the attacker gains access to NETCONF, which enables manipulation of network configuration across the entire SD-WAN fabric — a catastrophic compromise for organizations relying on SD-WAN for branch connectivity and network segmentation.
Cisco Talos tracks the exploitation activity as UAT-8616, assessed with high confidence to be a highly sophisticated cyber threat actor. Investigation revealed that malicious activity dates back at least three years to 2023, making this a long-running zero-day exploitation campaign. Investigation by intelligence partners (ACSC Australia) identified that UAT-8616 escalated to root via a version downgrade attack: the actor downgrades the SD-WAN software to a vulnerable version, exploits CVE-2022-20775 (CWE-25, path traversal via crafted username with '/../../' strings) for root privilege escalation, then restores the original software version to cover tracks.
The vulnerability affects all deployment types: On-Premises, Cisco Hosted SD-WAN Cloud, Cisco Hosted SD-WAN Cloud - Cisco Managed, and Cisco Hosted SD-WAN Cloud - FedRAMP Environment. Systems with internet-exposed management or control planes and exposed ports are at highest risk.
Post-compromise indicators include: unauthorized control connection peering events (especially vManage peer types from unknown IPs), creation and deletion of malicious user accounts with absent bash_history and cli-history, interactive root sessions with unauthorized SSH keys in /home/root/.ssh/authorized_keys (with PermitRootLogin set to yes), unauthorized SSH keys for vmanage-admin account, abnormally small or zero-byte log files (syslog, wtmp, lastlog, cli-history, bash_history), evidence of log clearing/truncation, unexplained peer additions/drops, and unauthorized version downgrade/upgrade cycles with system reboots.
The CISA added both CVE-2026-20127 and CVE-2022-20775 to the Known Exploited Vulnerabilities catalog on 2026-02-25, with a remediation due date of 2026-02-27 (2-day deadline reflecting emergency severity). CISA issued Emergency Directive 26-03. Multi-nation response: Cisco Talos (US), ACSC (Australia), NCSC (UK), CCCS (Canada) all issued coordinated advisories and hunt guides.
UAT-8616's targeting of SD-WAN controllers represents a critical escalation in the network edge device targeting trend. Compromising the SD-WAN controller gives an attacker the ability to reconfigure the entire overlay network, redirect traffic, intercept communications, and establish persistent access across all branch sites — far more impactful than compromising a single endpoint. Cisco released Snort rules 65938 and 65958 for detection.
Weaknesses (CWE)
CWE-287, CWE-25
Target sectors: critical-infrastructure, government, telecommunications, healthcare, energy, financial
Target regions: Global, Australia, United Kingdom, Canada, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20127, CVE-2022-20775, T1190, T1133, T1098.004, T1136.001, T1078.001, T1068, T1070.002, T1070.003, T1562.010, T1552.004