Skip to main content
List Directory
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Tech and Science
  • Health
Menu
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Tech and Science
  • Health

Cisco SD-WAN Flaw: Hackers Exploited Critical Vulnerability for Years – Joint Alert Issued

March 2, 2026 Sarah Wu - Tech Editor Tech and Science

A critical and previously undetected flaw in Cisco’s Catalyst SD-WAN products has been exploited by attackers for three years, prompting a rare joint warning from cybersecurity agencies in the US, UK, Australia, Canada and New Zealand. The vulnerability, tracked as CVE-2026-20127, allowed attackers to bypass authentication, gain privileged access, and steal data. The incident highlights the growing sophistication of espionage campaigns targeting network infrastructure and the challenges organizations face in maintaining robust security postures.

How the Attack Unfolded

The vulnerability, boasting a critical base score of 10.0 according to NIST’s National Vulnerability Database, enables attackers to remotely bypass authentication on affected Catalyst SD-WAN devices. Initial access didn’t immediately grant full control, but attackers were able to leverage this foothold to escalate privileges. A Talos Intelligence report details how attackers sent malicious requests to the vulnerable system to obtain an internal, highly privileged account.

However, the attackers didn’t stop there. Investigators, including the Australian government’s cyber security center, discovered a chained exploit. Attackers exploited a second vulnerability, CVE-2022-20775, by downgrading the SD-WAN controller to an older, vulnerable version. CVE-2022-20775, allows local, authenticated non-root users to gain root access. This allowed the attackers to create persistent accounts, effectively maintaining access even after the controller was restored to its original version. The attackers also actively attempted to cover their tracks by clearing logs, shell commands, and network connection history, as noted in the Australian government’s hunt guide.

The Unidentified Actor: UAT-8616

Currently, no threat actor has publicly claimed responsibility for the attacks. Researchers have been unable to definitively attribute the activity to a known group. However, the observed tactics, techniques, and procedures (TTPs) suggest a single, coordinated actor. This actor has been tentatively labeled UAT-8616 by security researchers, as reported by TechCrunch. The lack of attribution makes it hard to understand the attacker’s motivations and potential targets beyond those already compromised.

Impact and Affected Systems

The primary impact of this vulnerability is the potential for unauthorized access to sensitive data and the compromise of network infrastructure. Cisco Catalyst SD-WAN products are used by organizations of all sizes across various industries, making the potential attack surface significant. While the investigation hasn’t revealed evidence of lateral movement beyond the SD-WAN environment or command-and-control activity, the possibility remains a concern. The ability to create persistent access points raises the risk of future exploitation and further compromise.

Responding to the Threat: Mitigation and Detection

Cisco and the involved cybersecurity agencies have issued guidance for organizations using Catalyst SD-WAN products. The immediate priority is to review system logs for signs of compromise. Crucially, these logs should be forwarded off the appliance to prevent attackers from clearing them. Organizations are also advised to implement robust IP blocking measures and place controllers behind a firewall.

For detailed detection and mitigation strategies, organizations should consult resources from Cisco Talos, the NSA’s Joint Cybersecurity Advisory (available here), and their respective national cybersecurity agencies in the UK, Canada, and New Zealand.

The Broader Implications for Network Security

This incident underscores the increasing complexity of modern network security threats. The chained exploit, combining a zero-day vulnerability with an older, known flaw, demonstrates the importance of comprehensive vulnerability management and proactive threat hunting. The long dwell time – three years – before the vulnerability was discovered highlights the challenges of identifying and addressing hidden weaknesses in complex systems. The coordinated response from multiple national cybersecurity agencies signals the growing recognition of the need for international collaboration in addressing sophisticated cyber threats.

The incident also raises questions about the security of supply chains and the potential for vulnerabilities to be introduced through third-party components. SD-WAN technology, designed to improve network performance and agility, has turn into a critical component of many organizations’ infrastructure. Securing these systems is paramount to protecting sensitive data and maintaining business continuity.

Organizations should prioritize regular security assessments, penetration testing, and vulnerability scanning to identify and address potential weaknesses in their networks. Implementing robust logging and monitoring capabilities is also essential for detecting and responding to suspicious activity. Staying informed about the latest threat intelligence and security advisories is crucial for maintaining a proactive security posture.

More on this

  • PS5 Price Hike: Europe Could See €100 Increase – Slim & Pro Models Affected
  • Crimson Desert: First Impressions – A Promising But Rough Open-World RPG
cybersecurity

Recent Posts

  • Madison Keys vs. Hanne Vandewinkel Live: French Open 2026 TV Schedule and Streaming Guide
  • Our Strict Quality Control Process for Returned Clothing
  • German Business Sentiment Shows Slight Recovery in May According to Ifo Index
  • The 2-week supplement to avoid travel tummy trouble – plus blood clots worries – The Irish Sun
  • Ukraine Achieves Major Battlefield Successes as Russian Casualties Mount

Recent Comments

No comments to show.
List Directory

List-Directory is a comprehensive directory of businesses and services across the United States. Find what you need, when you need it.

Quick Links

  • Home
  • Privacy Policy
  • Terms of Service

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

Connect With Us

Official social links will appear here when available.

List-directory.com
For contact, advertising, copyright, issues email: office@list-directory.com

Privacy Policy Terms of Service