Active exploitation of CVE-2026-20127, a maximum-severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage), has escalated significantly following public disclosure. Honeypot telemetry and threat intelligence from researchers at Defused Cyber confirms 50+ unique source IPs observed globally within a 24-hour window, with attackers deploying multiple distinct webshell families and conducting post-exploitation enumeration and further remote code execution (RCE) activity. Critically, fingerprints consistent with the public proof-of-concept (PoC) were already appearing in the wild on February 26, 2026 - five days before the PoC's public release - indicating that sophisticated actors obtained or independently developed working exploit code well ahead of the broader threat actor community.
Vulnerability Overview: CVSS 10.0, No Workaround
Disclosed by Cisco on February 25, 2026 under advisory cisco-sa-sdwan-rpa-EHchtZk, CVE-2026-20127 carries a CVSS score of 10.0 - the maximum possible severity rating. The root cause is a broken peering authentication mechanism (CWE-287: Improper Authentication) in the SD-WAN control plane. An unauthenticated remote attacker can send crafted requests to an affected system to bypass authentication entirely and log in as an internal, high-privileged non-root user account. From this foothold, attackers can access NETCONF Cisco's network configuration protocol, enabling direct manipulation of SD-WAN fabric configuration across the entire overlay network. Cisco has confirmed no workaround is available; patching to a fixed release is the only complete remediation. The vulnerability affects both products regardless of device configuration, meaning deployment posture does not reduce exposure.
The vulnerability was originally identified and reported to Cisco by the Australian Signals Directorate's Australian Cyber Security Centre (ASD-ACSC), which simultaneously published a threat hunt guide and mitigation advisory. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 26-03 mandating Federal Civilian Executive Branch (FCEB) agencies to apply fixes within 24 hours, complete SD-WAN device inventories by February 26, and submit detailed remediation reports by March 5, 2026. CVE-2026-20127 and the related CVE-2022-20775 were simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
UAT-8616: A Sophisticated Threat Actor Exploiting This as a Zero-Day Since 2023
Cisco Talos attributes the exploitation campaign to a cluster designated UAT-8616, assessed with high confidence as a highly sophisticated threat actor. Talos researchers found forensic evidence of malicious activity dating back to at least 2023 meaning UAT-8616 possessed and weaponized this zero-day for approximately three years before public disclosure. Post-exploitation behavior follows a consistent pattern: after gaining initial access via the authentication bypass, UAT-8616 adds a rogue peer to the SD-WAN configuration, then leverages a software version downgrade exploiting CVE-2022-20775 to escalate privileges to root and establish long-term persistence within the SD-WAN environment. This chaining of vulnerabilities (CVE-2026-20127 for initial access + CVE-2022-20775 for privilege escalation) demonstrates deliberate, multi-stage tradecraft rather than opportunistic exploitation. While Cisco Talos has not publicly linked UAT-8616 to a known nation-state APT group, the three-year zero-day retention period, focus on critical infrastructure, and level of operational sophistication are consistent with a state-sponsored or state-adjacent actor.
Exploitation Now at Scale: Honeypot Telemetry and Webshell Families
Separate from the UAT-8616 campaign, the public disclosure of CVE-2026-20127 has triggered mass opportunistic exploitation. Honeypot intelligence collected by researchers at Defused Cyber through their Cisco SD-WAN honeypot intel stream confirms two distinct attacker profiles operating concurrently, identifiable by the webshell families being deployed:
- Type 1 Simple Exec Shells (Opportunistic): Basic bash
-cwrappers leveraging GET parameter execution, with command output piped directly back in the HTTP response. This pattern is characteristic of opportunistic mass-scanning actors using widely available exploit tooling with minimal customization. Low sophistication; high volume. - Type 2 Behinder-Style Encrypted Implants (Sophisticated): A significantly more advanced implant class using AES-encrypted command-and-control communications with a hardcoded key. Payloads are loaded dynamically via in-memory Java classloading no payload ever touches disk, defeating filesystem-based forensic analysis and most endpoint detection mechanisms. Implants are session-persistent across requests, maintaining operator state between connections. Response framing uses a key-derived MD5 marker to authenticate legitimate C2 operator responses and filter out honeypot or researcher interference. This implant profile is consistent with a prepared, pre-positioned toolkit rather than opportunistic tooling deployed post-exploitation.
The coexistence of Type 1 and Type 2 activity on the same vulnerability indicates that CVE-2026-20127 is now simultaneously being exploited by at least two distinct attacker populations: commodity actors using automation for mass access harvesting, and skilled operators deploying purpose-built, anti-forensic implants for persistent access.
Observed Attack Infrastructure: Sample IOCs
The following IP addresses have been observed in active exploitation attempts, sourced from Defused Cyber's SD-WAN honeypot telemetry. Attribution of ASN and organization is provided for defensive context Tor exit node and cloud hosting IPs are commonly used for source anonymization and should not be treated as indicative of the operator's actual geographic location:
- 185.220.101[.]5 (DE) Stiftung Erneuerbare Freiheit, Tor exit node
- 111.194.207[.]46 (CN) China Unicom Beijing
- 115.190.164[.]9 (CN) Beijing Volcano Engine
- 101.36.107[.]228 (HK) UCLOUD Information Technology
- 149.88.106[.]161 (SG) Datacamp Limited
- 46.31.76[.]145 (TR) TEKNOSOS Bilisim
- 134.65.30[.]157 (BR) Oracle Corporation
- 83.142.209[.]48 (LU) Ghosty Networks LLC
- 180.76.172[.]156 (CN) Beijing Baidu Netcom
- 192.159.99[.]168 (US) 1337 Services GmbH
The geographic and ASN diversity of observed source IPs spanning Tor exit infrastructure, Chinese cloud providers, and anonymous VPS hosting across four continents is consistent with a distributed botnet or coordinated multi-operator campaign using disposable or obfuscated attack infrastructure. The presence of multiple Chinese ASN-sourced IPs is noted, though attribution of exploitation to a specific actor based solely on source IP is assessed as unreliable given the prevalence of proxy and cloud anonymization.
Affected Versions and Patch Guidance
CVE-2026-20127 affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. Fixed releases are available for the following versions:
- 20.9.x: Upgrade to 20.9.8.2 or above
- 20.12.5.x: Upgrade to 20.12.5.3 or above
- 20.12.6.x: Upgrade to 20.12.6.1 or above
- 20.13.x / 20.14.x / 20.15.x: Upgrade to 20.15.4.2 or above
- 20.16.x / 20.18.x: Upgrade to 20.18.2.1 or above
Cisco notes that versions 20.11, 20.13, 20.14, 20.16, and versions prior to 20.9 have reached End of Software Maintenance and customers must migrate to a supported release. As there is no workaround, organizations running internet-exposed SD-WAN management planes should treat patching as a P0 remediation task.
Detection and Threat Hunting Guidance
For organizations that have not yet patched or that patched without first assessing for prior compromise the following detection steps are recommended based on Cisco Talos and ASD-ACSC guidance:
- Control connection peering events: Review Cisco Catalyst SD-WAN logs for any control connection peering events. All such events require manual validation verify timestamp against known maintenance windows, confirm the source IP belongs to authorized infrastructure, and validate that the peer system IP matches documented device assignments in the SD-WAN topology.
- Auth log review: Audit
/var/log/auth.logfor entries containingAccepted publickey for vmanage-adminfrom unknown or unauthorized IP addresses. Cross-reference all source IPs against configured System IPs listed in Cisco Catalyst SD-WAN Manager WebUI under Devices > System IP. - CVE-2022-20775 path traversal indicators: Search logs for username strings containing path traversal patterns such as
/../../or/ &../ &../, which are indicative of privilege escalation chaining. - Version downgrade events: Unexplained software version downgrades or unexpected reboot events are a documented post-exploitation indicator for UAT-8616 activity and should trigger immediate incident response.
- NETCONF activity: Review NETCONF session logs for unauthorized configuration modifications, particularly the addition of unknown peer connections to the SD-WAN fabric.
Intelligence Assessment
CVE-2026-20127 presents a threat profile of exceptional severity along multiple dimensions simultaneously: a CVSS 10.0 score, confirmed zero-day exploitation dating to 2023 by a sophisticated actor, no available workaround, and now mass opportunistic exploitation following public PoC release. The appearance of Behinder-style in-memory implants with AES-encrypted C2 within days of public disclosure strongly suggests that at least one sophisticated actor beyond UAT-8616 had pre-positioned tooling for this vulnerability or rapidly adapted existing SD-WAN exploitation frameworks. IntelFusions assesses with high confidence that organizations with internet-exposed Cisco Catalyst SD-WAN management planes that have not yet patched should treat themselves as potentially compromised and initiate forensic review in parallel with patching, rather than treating patch application as sufficient remediation on its own. The long exploitation window (2023–2026) means that UAT-8616-attributed compromise may have persisted undetected for years in some environments.
This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. IOCs are sourced from public honeypot telemetry and should be validated before operational use. Claims described herein have not been independently verified unless explicitly stated.