CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0)

CVE-2026-20127 (TL-2026-0236), also tracked as cisco-sa-sdwan-rpa-EHchtZk, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-16. It is attributed to UAT-8616 (China) with medium confidence, affects Cisco Catalyst SD-WAN Manager (vManage), references 6 CVEs (CVE-2026-20127, CVE-2022-20775, CVE-2026-20128), maps to 15 MITRE ATT&CK techniques (T1021, T1059, T1068), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-0236

Threat ID
TL-2026-0236
Also known as
cisco-sa-sdwan-rpa-EHchtZk, CSCws52722, ED 26-03
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-03-16
Last reviewed
2026-03-16
Attribution
UAT-8616
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
critical-infrastructure, government, defense, telecommunications, financial, healthcare, energy
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
23

Malware and tooling in CVE-2026-20127

Malware and tooling: NETCONF (RFC 6241)

A maximum-severity authentication bypass vulnerability (CVSS 10.0) in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass peering authentication via crafted NETCONF requests, gaining administrative access. Actively exploited as a zero-day by sophisticated threat actor UAT-8616 since at least 2023, targeting critical infrastructure. CISA issued Emergency Directive ED 26-03 mandating immediate federal remediation.

How CVE-2026-20127 works

CVE-2026-20127 is a critical improper authentication vulnerability (CWE-287) in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage). The flaw resides in the peering authentication mechanism, which fails to properly validate authentication for control plane connections. An unauthenticated remote attacker can exploit this by sending crafted requests to bypass authentication and log in as an internal high-privileged non-root user account (vmanage-admin), gaining NETCONF access to manipulate SD-WAN fabric configuration. The vulnerability affects all deployment models including on-premises, Cisco Hosted SD-WAN Cloud, Cisco Managed, and FedRAMP environments. Approximately 600 Cisco SD-WAN Manager instances are internet-facing, with nearly 25% also exposing ports 22 (SSH) or 830 (NETCONF). Cisco Talos Intelligence attributed active exploitation to UAT-8616, a highly sophisticated threat actor whose activity dates back to at least 2023 — three years before public disclosure. The observed attack chain is multi-stage: after initial authentication bypass via CVE-2026-20127, the actor adds a rogue peer to the SD-WAN control plane, deliberately downgrades the system software version to one vulnerable to CVE-2022-20775 (a CLI privilege escalation via path traversal), exploits it to achieve root access, then restores the original software version to complicate detection. Post-compromise activities include creation and deletion of malicious local user accounts mimicking legitimate ones, injection of unauthorized SSH keys into /home/root/.ssh/authorized_keys and vmanage-admin accounts, modification of /etc/ssh/sshd_config to enable PermitRootLogin, lateral movement via NETCONF (port 830) and SSH across the management and control planes, establishment of rogue peer connections, and systematic evidence destruction through log truncation and history clearing. A public proof-of-concept exploit published by zerozenxlabs on GitHub demonstrates a four-phase attack chain: (1) unauthenticated retrieval of DCA credentials via the /reports/data/opt/data/containers/config/data-collection-agent/.dca endpoint, (2) authentication bypass using the viptela-reserved-dca system account, (3) path traversal exploitation on /dataservice/smartLicensing/uploadAck to deploy a malicious WAR file containing a JSP webshell (cmd.jsp), and (4) remote code execution through the deployed webshell at /cmd.gz/cmd.jsp. CISA added CVE-2026-20127 to the Known Exploited Vulnerabilities catalog on February 25, 2026, and issued Emergency Directive ED 26-03 requiring federal agencies to inventory all SD-WAN systems, apply patches, assess compromise, and report remediation within strict deadlines. No workarounds are available — patching is the only mitigation. Related vulnerabilities disclosed in the same campaign include CVE-2026-20128 (DCA credential file exposure, CVSS 7.5), CVE-2026-20122 (API file overwrite, CVSS 5.4), CVE-2026-20129 (unauthenticated netadmin access, CVSS 9.8), and CVE-2026-20126 (low-privilege escalation to root, CVSS 8.8).

MITRE ATT&CK techniques used in TL-2026-0236

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

execution

T1059 Command and Scripting Interpreter

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts

command-and-control

T1090 Proxy

persistence

T1098 Account Manipulation; T1133 External Remote Services; T1136 Create Account; T1505 Server Software Component

initial-access

T1190 Exploit Public-Facing Application

impact

T1498 Network Denial of Service

credential-access

T1552 Unsecured Credentials

Affected products and versions in CVE-2026-20127

  • Cisco — Catalyst SD-WAN Manager (vManage)
    Vulnerable versions: prior to 20.9; 20.9 to 20.9.8.1; 20.11; 20.12 to 20.12.5.2; 20.12.6; 20.13; 20.14; 20.15 to 20.15.4.1; 20.16; 20.18 to 20.18.2.0
    Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1
  • Cisco — Catalyst SD-WAN Controller (vSmart)
    Vulnerable versions: prior to 20.9; 20.9 to 20.9.8.1; 20.11; 20.12 to 20.12.5.2; 20.12.6; 20.13; 20.14; 20.15 to 20.15.4.1; 20.16; 20.18 to 20.18.2.0
    Fixed in: 20.9.8.2; 20.12.5.3; 20.12.6.1; 20.15.4.2; 20.18.2.1

Remediation for CVE-2026-20127

Patches

  • Cisco Catalyst SD-WAN 20.9: Upgrade to 20.9.8.2 or later
  • Cisco Catalyst SD-WAN 20.11: Upgrade to 20.12.6.1 or later (20.11 is EOM)
  • Cisco Catalyst SD-WAN 20.12.5: Upgrade to 20.12.5.3 or later
  • Cisco Catalyst SD-WAN 20.12.6: Upgrade to 20.12.6.1 or later
  • Cisco Catalyst SD-WAN 20.13/20.14: Upgrade to 20.15.4.2 or later (EOM releases)
  • Cisco Catalyst SD-WAN 20.15: Upgrade to 20.15.4.2 or later
  • Cisco Catalyst SD-WAN 20.16: Upgrade to 20.18.2.1 or later (EOM release)
  • Cisco Catalyst SD-WAN 20.18: Upgrade to 20.18.2.1 or later
  • Cisco Catalyst SD-WAN prior to 20.9: Migrate to a supported fixed release

Immediate actions

  • Apply Cisco security patches immediately — no workarounds available
  • Restrict access to ports 22 (SSH) and 830 (NETCONF) via ACLs and firewall rules to authorized management IPs only
  • Audit /var/log/auth.log for Accepted publickey for vmanage-admin from unauthorized IP addresses
  • Inventory all Cisco SD-WAN Controller and Manager systems across all deployment types
  • Review /home/root/.ssh/authorized_keys and /home/vmanage-admin/.ssh/authorized_keys for unauthorized entries
  • Check /etc/ssh/sshd_config for unauthorized PermitRootLogin changes
  • Validate all SD-WAN peer connections against authorized topology documentation

Workarounds

  • No workarounds available per Cisco advisory — patching is mandatory

Longer-term hardening

  • Implement network segmentation isolating SD-WAN management plane from general network access
  • Deploy continuous monitoring for control connection peering events and cross-reference against authorized asset inventories
  • Establish baseline of authorized System IPs and peer relationships for anomaly detection
  • Implement SIEM alerting on log truncation events and 0-byte log files on SD-WAN infrastructure
  • Enable comprehensive audit logging with off-device log forwarding to prevent evidence destruction
  • Conduct periodic threat hunting using CISA/ACSC hunt guide methodologies

CVEs associated with CVE-2026-20127

CVE-2026-20127, CVE-2022-20775, CVE-2026-20128, CVE-2026-20122, CVE-2026-20129, CVE-2026-20126

Weaknesses (CWE) in CVE-2026-20127

CWE-287

Timeline of CVE-2026-20127

  • UAT-8616 begins active zero-day exploitation of CVE-2026-20127 against critical infrastructure targets, as later confirmed by Cisco Talos with evidence dating back at least three years
  • Cisco Talos Intelligence publishes detailed analysis attributing exploitation to UAT-8616, a highly sophisticated threat actor targeting critical infrastructure via SD-WAN zero-day
  • CISA adds CVE-2026-20127 and CVE-2022-20775 to Known Exploited Vulnerabilities catalog, mandating federal agency remediation
  • Cisco publicly discloses CVE-2026-20127 with maximum CVSS 10.0 score, confirms active exploitation, and releases security advisory cisco-sa-sdwan-rpa-EHchtZk with patches
  • Australian Signals Directorate ACSC publishes joint threat hunting guide co-authored with CISA, NSA, Canadian Cyber Centre, NZ NCSC, and UK NCSC for detecting CVE-2026-20127 compromise
  • CISA issues Emergency Directive ED 26-03 requiring federal agencies to inventory SD-WAN systems by 11:59 PM ET February 26, submit detailed inventory by March 5, and complete hardening by March 26
  • CISA KEV remediation deadline for federal agencies; Cisco releases 20.9.8.2 patch for the oldest supported release train
  • Public proof-of-concept exploit published on GitHub by zerozenxlabs demonstrating four-phase pre-authentication RCE attack chain including DCA credential theft, auth bypass, WAR upload, and JSP webshell deployment
  • Federal agency detailed inventory submission deadline under CISA Emergency Directive ED 26-03
  • Cisco discloses additional related vulnerabilities CVE-2026-20128, CVE-2026-20122, CVE-2026-20129, and CVE-2026-20126 affecting the same SD-WAN product family
  • Intel 471 publishes comprehensive analysis of CVE-2026-20127 exploitation campaign and attack patterns targeting enterprise SD-WAN infrastructure
  • CISA Emergency Directive ED 26-03 hardening completion reporting deadline for federal agencies
  • As of 2026-05-29, CVE-2026-20127 is patched (CISA KEV, ED 26-03 deadline May 17) but remains actively exploited against unpatched Cisco SD-WAN by ~10 threat clusters through May 2026. Lead actor UAT-8616 pivoted to successor zero-day CVE-2026-20182 (separate vdaemon flaw, tracked as TL-2026-0516), so the campaign continues.

Sources cited for CVE-2026-20127

Threats related to CVE-2026-20127

Detection coverage for TL-2026-0236

As of 2026-03-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0236 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats