Image for Article: Cisco SD-WAN Zero-Day Under Exploitation for 3 Years

Article Details

Title
Article: Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
Impact Score
7 / 10
AI Summary (Processed Content)

A critical zero-day vulnerability (CVE-2026-20127) in Cisco's SD-WAN Controller has been actively exploited by a sophisticated, unidentified threat actor for at least three years. The flaw allows authentication bypass and, when chained with a second vulnerability (CVE-2022-20775), provides root access. U.S. and international cybersecurity agencies have issued urgent patching directives, noting the actor's highly stealthy operations left minimal evidence and showed no lateral movement beyond the SD-WAN systems. The main topics covered are the severe vulnerability's exploitation, the emergency response from authorities, and the mysterious nature of the threat actor tracked as UAT-8616.

Original URL
https://www.darkreading.com/vulnerabilities-threats/cisco-sd-wan-zero-day-exploitation-3-years
Source Feed
darkreading
Published Date
2026-02-26 21:45
Fetched Date
2026-03-04 13:40
Processed Date
2026-03-04 13:52
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content