INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco SD-WAN Zero-Day Exploited for 3 Years

| 2026-03-13 11:27 CRITICAL HIGH
Executive Summary AI-generated
The US government agencies are facing a critical deadline to reclaim their networks from intruders who have been hiding in the system for years. A group of hackers, currently called UAT-8616, has exploited a flaw in Cisco Catalyst SD-WAN systems, allowing them to exploit digital switchboards that manage internet traffic for the US government. Experts are watching for any remaining signs of the hackers across the entire federal government. The Cybersecurity and Infrastructure Security Agency (CISA) first sounded the alarm on 25 February 2026 with an initial emergency directive after investigators found a flaw in Cisco Catalyst SD-WAN systems. This allows experts to watch for any remaining signs of the hackers, who have likely continued to exploit vulnerabilities despite CISA's efforts. The problem lies with a flaw known as CVE-2026-20127, which has a maximum CVSS rating of 10 and poses an unacceptable risk to Federal Civilian Executive Branch agencies. A "Perfect 10" Risk is at play here - the flaw allows attackers to log in as internal users, manipulate network configuration for the SD-WAN fabric, and access sensitive data. The cleanup process will continue through spring, with all agencies required to send their internal traffic logs to CISA's central monitoring system by March 23rd. A final report on whether networks are finally safe is due May 1st.
Technical Mitigations AI-generated
* Implement a robust patch management system to ensure timely and effective deployment of security patches, including the use of automated testing and validation processes. * Conduct regular vulnerability assessments and penetration testing (VSTs) on Cisco SD-WAN systems to identify potential vulnerabilities and weaknesses before they can be exploited by attackers. * Use secure coding practices in software development to prevent exploitation of known vulnerabilities like CVE-2026-20127, such as using secure authentication mechanisms and validating user input. * Consider implementing a network segmentation strategy to isolate sensitive data and traffic from the rest of the network, reducing the attack surface for potential intruders.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt TyphoonVolt TyphoonVolt Typhoon CVE-2022-20775CVE-2022-20775 CVE-2026-20127CVE-2026-20127
Target & Sectors
NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES governmentgovernment technologytechnology
Incident Timeline
late 2025
The US Centers for Disease Control and Prevention (CISA) faced a potential deadline to address the recently discovered Critical Vulnerability Exploit (CVE-2026-20127) in Cisco's SD-WAN products.
vulnerability CVE-2026-20127
February 21
GitLab is to be addressed by February 21.
attribution GitLab
2026-02-25
Threat actors used a newly discovered critical Cisco SD-WAN flaw to target US agencies yesterday.
general_metric 2022 bug
25 February 2026
The US government agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), were set to face a deadline on 25 February 2026 due to an initial emergency directive issued by CISA after UAT-8616 hackers exploited a critical Cisco Catalyst SD-WAN flaw in digital switchboards.
industry Government
attribution UAT-8616
target_region United States
February 2026
Threat actors used a Cisco SD-WAN flaw to gain unauthorized access to the NETCONF protocol, allowing them to manipulate network configuration and potentially log in as an internal user account.
organisation Cisco Catalyst SD-WAN Controller
organisation NETCONF
organisation SD-WAN
organisation Long-Term Cleanup
February 26, 2026
Hackers used Cisco SD-WAN zero-day CVE-2026-20127 to gain full admin control of US agencies since 2023.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-20127
2026-02-26
Cisco's Catalyst SD-WAN Controller is vulnerable to a zero-day flaw that has been exploited in the wild for at least three years.
organisation Catalyst SD-WAN Controller
February 27, 2026
Threat actors used GitLab to target the US federal agencies.
source_region United States
general_metric 5 pm
attribution GitLab
27 February
Threat actors used a critical Cisco SD-WAN flaw to target US agencies, affecting the following products: On-Prem Deployment, Cisco Hosted SD-WAN Cloud and FedRAMP Environment.
organisation Cisco Hosted SD-WAN Cloud
11 March
CISA has released a directive requiring US agencies to report on the hardening steps taken by 11 March.
attribution CISA
2026-03-13
Threat actors used the built-in update mechanism to downgrade a vSmart controller to an earlier version with known local privilege escalation vulnerabilities, including CVE-2022-20775.
organisation National Cyber Security Centre
organisation NCSC
organisation CVE-2022-20775
organisation vSmart
organisation CLI
organisation CVE-2022
organisation Catalyst
organisation Cisco SD-WAN
organisation SD-WAN vSmart
organisation Cisco Catalyst SD-WAN
organisation SD-WAN vManage
organisation CVSS
organisation CVE-2026
organisation Microsoft Patches
organisation the Cisco SD-WAN
infrastructure N8N
organisation Cisco Catalyst SD-WAN Controller
organisation NETCONF
organisation SD-WAN
organisation Immediate Actions
organisation Catalyst SD-WAN Controller
organisation Cisco SD-WAN Zero-Day
organisation NMS
threat_actor Salt Typhoon
threat_actor Volt Typhoon
organisation Critical Infrastructure
organisation CI
organisation Catalyst SD-WAN Controllers
organisation UI
infrastructure 20.9.8
infrastructure 20.12.5
infrastructure 20.12.6
infrastructure 20.15.4
infrastructure 20.18.2
infrastructure 20.9.1
organisation Cisco Hosted SD-WAN Cloud
organisation Cisco
organisation the Australian Signals Directorate’s
organisation IPs
organisation TAC
organisation the Cisco Catalyst SD-WAN
23 March
US agencies are due to receive CISA's central monitoring system by 23 March, with all internal traffic logs required.
1 May 2026
US agencies face a critical Cisco SD-WAN flaw deadline of 1 May 2026 due to the final report on whether networks are safe.
organisation Homeland Security
May 2026
Threat actors are expected to exploit a critical Cisco SD-WAN flaw by May 2026.
organisation Cisco SD-WAN
Tactical Metrics
Metrics
infrastructure
​N8N
Affected Product
Metrics
infrastructure
​20.9.8
Software Version
Metrics
infrastructure
​20.12.5
Software Version
Metrics
infrastructure
​20.12.6
Software Version
Metrics
infrastructure
​20.15.4
Software Version
Metrics
infrastructure
​20.18.2
Software Version
Metrics
infrastructure
​20.9.1
Software Version