CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation
CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day (TL-2026-0166), also tracked as cisco-sa-sdwan-rpa-EHchtZk, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-02. It is attributed to UAT-8616 (China) with high confidence, affects Cisco Catalyst SD-WAN Controller (vSmart), references 2 CVEs (CVE-2026-20127, CVE-2022-20775), maps to 19 MITRE ATT&CK techniques (T0831, T1021.004, T1039), and is covered by 4 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0166
- Threat ID
- TL-2026-0166
- Also known as
- cisco-sa-sdwan-rpa-EHchtZk, ED 26-03
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- SUPERSEDED
- Category
- VULNERABILITY
- First published
- 2026-03-02
- Last reviewed
- 2026-03-02
- Attribution
- UAT-8616
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Detection rules
- 4
- Indicators of compromise
- 27
Critical authentication bypass zero-day (CVE-2026-20127, CVSS 9.8) in Cisco Catalyst SD-WAN Controller (vSmart) and SD-WAN Manager (vManage) under active exploitation by sophisticated threat actor UAT-8616 since at least 2023. Chained with CVE-2022-20775 path traversal for root access via software version downgrade attack. Joint advisories from CISA (Emergency Directive ED 26-03), NCSC UK, and ACSC Australia. Targets critical infrastructure SD-WAN control plane.
How CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day works
CVE-2026-20127 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage). The vulnerability exists because the peering authentication mechanism is not working properly, allowing an unauthenticated remote attacker to send crafted requests and gain administrative privileges as an internal high-privileged non-root user account. Using this access, the attacker can reach NETCONF and manipulate SD-WAN fabric configuration.
Cisco Talos tracks the exploitation activity as UAT-8616, assessed with high confidence to be a highly sophisticated cyber threat actor. Investigation revealed exploitation dating back to at least 2023, making this a multi-year zero-day campaign. Post-exploitation, UAT-8616 adds rogue peer devices that appear as legitimate SD-WAN components, then escalates to root access through a software version downgrade attack chained with CVE-2022-20775 (path traversal for privilege escalation). After achieving root, the actor restores the original software version to evade detection.
The attack chain targets the SD-WAN control plane — the most sensitive component managing connectivity across sites and clouds. UAT-8616 demonstrates sophisticated tradecraft including rogue peering with anomalous 'remote-color' values, creation and deletion of malicious user accounts, SSH key injection for vmanage-admin and root accounts, comprehensive log clearing (syslog, wtmp, lastlog, cli-history, bash_history), and configuration manipulation via NETCONF. International partners (ACSC Australia) observed lateral movement outside the SD-WAN environment.
CISA issued Emergency Directive ED 26-03 on 2026-02-25 requiring federal agencies to inventory, collect forensic artifacts, patch by 5:00 PM ET February 27, and conduct threat hunting following the ACSC-led joint hunt guide. The vulnerability affects all deployment types: on-prem, Cisco Hosted SD-WAN Cloud, Cisco Managed, and FedRAMP environments. No workarounds exist — patching is the only durable fix. Cisco released Snort rules 65938 and 65958 for network detection.
MITRE ATT&CK techniques used in TL-2026-0166
Impact
lateral-movement
collection
T1039 Data from Network Shared Drive
discovery
T1046 Network Service Discovery
execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
stealth
T1070.003 Clear Command History; T1070.006 Timestomp; T1078.001 Default Accounts
command-and-control
T1090.003 Multi-hop Proxy; T1219 Remote Access Tools
persistence
T1098.004 SSH Authorized Keys; T1136.001 Local Account
initial-access
T1190 Exploit Public-Facing Application
impact
T1498 Network Denial of Service
credential-access
defense-impairment
T1601.002 Downgrade System Image; T1685 Disable or Modify Tools; T1685.006 Clear Linux or Mac System Logs
Affected products and versions in CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
- Cisco — Catalyst SD-WAN Controller (vSmart)
Vulnerable versions: < 20.9.8.2; 20.11.x; 20.12.x < 20.12.5.3; 20.13.x; 20.14.x; 20.15.x < 20.15.4.2; 20.16.x; 20.18.x < 20.18.2.1
Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1 - Cisco — Catalyst SD-WAN Manager (vManage)
Vulnerable versions: < 20.9.8.2; 20.11.x; 20.12.x < 20.12.5.3; 20.13.x; 20.14.x; 20.15.x < 20.15.4.2; 20.16.x; 20.18.x < 20.18.2.1
Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1
Remediation for CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
Patches
- Cisco Catalyst SD-WAN 20.9.8.2
- Cisco Catalyst SD-WAN 20.12.5.3
- Cisco Catalyst SD-WAN 20.12.6.1
- Cisco Catalyst SD-WAN 20.15.4.2
- Cisco Catalyst SD-WAN 20.18.2.1
Immediate actions
- Apply Cisco fixed software releases immediately (20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, 20.18.2.1)
- Restrict network exposure — place SD-WAN control components behind firewalls
- Restrict port 22 and port 830 traffic to known controller IPs only via ACLs
- Forward SD-WAN logs to external centralized systems immediately
- Collect admin-tech output from all control components for forensic review
Workarounds
- No workarounds fully address CVE-2026-20127 — patching is the only complete remediation
- Temporary mitigation: restrict intra-controller connectivity per Cisco Firewall Ports guide
- Isolate management interfaces from untrusted networks
Longer-term hardening
- Deploy fresh vManage, vSmart, and vBond from patched OVA/qcow2 images if root compromise confirmed
- Migrate edges to new infrastructure with new admin accounts and unique credentials
- Implement Cisco Catalyst SD-WAN Hardening Guide recommendations
- Audit all authorized_keys files for vmanage-admin and root accounts
- Baseline authorized SSH key fingerprints and monitor for unauthorized additions
CVEs associated with CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
Weaknesses (CWE) in CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
CWE-287
Timeline of CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
Showing the 20 most recent tracked events.
- CVE-2022-20775 published — Cisco SD-WAN CLI path traversal privilege escalation vulnerability
- Earliest known exploitation by UAT-8616 — Cisco Talos assessment with high confidence that activity dates to at least 2023
- Earliest known exploitation by UAT-8616 — Cisco Talos assessment with high confidence that activity dates to at least 2023
- ACSC-led Cisco SD-WAN Threat Hunt Guide published jointly with CISA and international partners — detection guidance for rogue peering, SSH abuse, log clearing, version downgrades.
- CISA issues Emergency Directive ED 26-03 requiring FCEB agencies to patch by 5:00 PM ET Feb 27. NCSC UK and ACSC Australia issue joint advisories.
- Cisco releases security advisory cisco-sa-sdwan-rpa-EHchtZk with fixed software releases. CWE-287 authentication bypass confirmed.
- Cisco Talos publishes active exploitation advisory for CVE-2026-20127 — UAT-8616 SD-WAN campaign. Source: https://blog.talosintelligence.com/uat-8616-sd-wan/
- ACSC-led Cisco SD-WAN Threat Hunt Guide published jointly with CISA and international partners — detection guidance for rogue peering, SSH abuse, log clearing, version downgrades.
- CISA issues Emergency Directive ED 26-03 requiring FCEB agencies to patch by 5:00 PM ET Feb 27. NCSC UK and ACSC Australia issue joint advisories.
- Cisco releases security advisory cisco-sa-sdwan-rpa-EHchtZk with fixed software releases. CWE-287 authentication bypass confirmed.
- Cisco Talos publishes active exploitation advisory for CVE-2026-20127 — UAT-8616 SD-WAN campaign. Source: https://blog.talosintelligence.com/uat-8616-sd-wan/
- SOC Prime and Sophos publish technical analysis. Sophos releases IPS rules 65938 and 65958. SOC Prime provides SIEM detection content.
- SOC Prime and Sophos publish technical analysis. Sophos releases IPS rules 65938 and 65958. SOC Prime provides SIEM detection content.
- CISA Emergency Directive ED 26-03 patch deadline — 5:00 PM ET. Federal agencies required to have applied fixed releases.
- CISA Emergency Directive ED 26-03 patch deadline — 5:00 PM ET. Federal agencies required to have applied fixed releases.
- NCSC CTO weekly summary highlights Cisco SD-WAN exploitation as top operational concern. SentinelOne coverage published.
- NCSC CTO weekly summary highlights Cisco SD-WAN exploitation as top operational concern. SentinelOne coverage published.
- CISA ED 26-03 second reporting deadline — detailed inventory, artifact collection, CVE updates, and hunting results due by 11:59 PM ET.
- CISA ED 26-03 second reporting deadline — detailed inventory, artifact collection, CVE updates, and hunting results due by 11:59 PM ET.
- As of 2026-05-29, CVE-2026-20127 is patched (Cisco fixes Feb 25, in CISA KEV, ED 26-03 deadline passed Feb 27) so this specific vector is closed. The UAT-8616 SD-WAN campaign continues via successor CVE-2026-20182 (CVSS 10.0), a near-identical auth bypass Cisco patched amid active exploitation on May 14-15, superseding this entry.
Sources cited for CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
- Cisco Talos: Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
- Cisco Security Advisory: cisco-sa-sdwan-rpa-EHchtZk
- CISA Emergency Directive ED 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems
- CISA Supplemental Direction ED 26-03: Hunt and Hardening Guidance for Cisco SD-WAN Systems
- NCSC UK: Exploitation of Cisco Catalyst SD-WANs
- ACSC Hunt Guide: Cisco SD-WAN Threat Hunt Guide
- SOC Prime: CVE-2026-20127 Cisco SD-WAN Zero-Day Exploited Since 2023
- Sophos: Cisco SD-WAN vulnerabilities CVE-2026-20127 and CVE-2022-20775 in active exploitation
- Cisco Catalyst SD-WAN Hardening Guide
- NCSC CTO Summary: Week ending March 1st — Cisco SD-WAN exploitation highlighted
- SentinelOne: The Good, the Bad and the Ugly in Cybersecurity — Week 9
- Canadian Centre for Cyber Security: Advisory AL26-004 — Critical Vulnerability Affecting Cisco Catalyst SD-WAN
Threats related to CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day
- Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting
- CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0)
- Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)
Detection coverage for TL-2026-0166
As of 2026-03-02, Threadlinqs Intelligence publishes 4 detection rule(s) for TL-2026-0166 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.