CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0) — Threadlinqs Intelligence
As of 2026-05-30, CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0) is a critical-severity vulnerability threat attributed to UAT-8616 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0236 · Severity: CRITICAL · CVSS: 10 · Status: MONITORING · Category: VULNERABILITY
Attribution: UAT-8616 · China · ESPIONAGE
A maximum-severity authentication bypass vulnerability (CVSS 10.0) in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass peering authentication via crafted
CVE-2026-20127 is a critical improper authentication vulnerability (CWE-287) in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage). The flaw resides in the peering authentication mechanism, which fails to properly validate authentication for control plane connections. An unauthenticated remote attacker can exploit this by sending crafted requests to bypass authentication and log in as an internal high-privileged non-root user account (vmanage-admin), gaining NETCONF access to manipulate SD-WAN fabric configuration.
The vulnerability affects all deployment models including on-premises, Cisco Hosted SD-WAN Cloud, Cisco Managed, and FedRAMP environments. Approximately 600 Cisco SD-WAN Manager instances are internet-facing, with nearly 25% also exposing ports 22 (SSH) or 830 (NETCONF).
Cisco Talos Intelligence attributed active exploitation to UAT-8616, a highly sophisticated threat actor whose activity dates back to at least 2023 — three years before public disclosure. The observed attack chain is multi-stage: after initial authentication bypass via CVE-2026-20127, the actor adds a rogue peer to the SD-WAN control plane, deliberately downgrades the system software version to one vulnerable to CVE-2022-20775 (a CLI privilege escalation via path traversal), exploits it to achieve root access, then restores the original software version to complicate detection.
Post-compromise activities include creation and deletion of malicious local user accounts mimicking legitimate ones, injection of unauthorized SSH keys into /home/root/.ssh/authorized_keys and vmanage-admin accounts, modification of /etc/ssh/sshd_config to enable PermitRootLogin, lateral movement via NETCONF (port 830) and SSH across the management and control planes, establishment of rogue peer connections, and systematic evidence destruction through log truncation and history clearing.
A public proof-of-concept exploit published by zerozenxlabs on GitHub demonstrates a four-phase attack chain: (1) unauthenticated retrieval of DCA credentials via the /reports/data/opt/data/containers/config/data-collection-agent/.dca endpoint, (2) authentication bypass using the viptela-reserved-dca system account, (3) path traversal exploitation on /dataservice/smartLicensing/uploadAck to deploy a malicious WAR file containing a JSP webshell (cmd.jsp), and (4) remote code execution through the deployed webshell at /cmd.gz/cmd.jsp.
CISA added CVE-2026-20127 to the Known Exploited Vulnerabilities catalog on February 25, 2026, and issued Emergency Directive ED 26-03 requiring federal agencies to inventory all SD-WAN systems, apply patches, assess compromise, and report remediation within strict deadlines. No workarounds are available — patching is the only mitigation.
Related vulnerabilities disclosed in the same campaign include CVE-2026-20128 (DCA credential file exposure, CVSS 7.5), CVE-2026-20122 (API file overwrite, CVSS 5.4), CVE-2026-20129 (unauthenticated netadmin access, CVSS 9.8), and CVE-2026-20126 (low-privilege escalation to root, CVSS 8.8).
Target sectors: critical-infrastructure, government, defense, telecommunications, financial, healthcare, energy
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20127, CVE-2022-20775, CVE-2026-20128, CVE-2026-20122, CVE-2026-20129, CVE-2026-20126, T1190, T1133, T1059, T1505, T1136, T1098, T1068, T1078, T1070, T1070