CVE-2026-20127: Active Exploitation at Scale of Cisco Catalyst SD-WAN Zero-Day - Webshell Deployment, Sophisticated Implants, and 50+ Attack IPs Observed

Active exploitation of CVE-2026-20127, a maximum-severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage), has escalated significantly following public disclosure. Honeypot telemetry and threat intelligence from researchers at Defused Cyber confirms 50+ unique source IPs observed globally within a 24-hour window, with attackers deploying multiple distinct webshell families and conducting post-exploitation enumeration and further remote code execution (RCE) activity. Critically, fingerprints consistent with the public proof-of-concept (PoC) were already appearing in the wild on February 26, 2026 - five days before the PoC's public release - indicating that sophisticated actors obtained or independently developed working exploit code well ahead of the broader threat actor community.

Vulnerability Overview: CVSS 10.0, No Workaround

Disclosed by Cisco on February 25, 2026 under advisory cisco-sa-sdwan-rpa-EHchtZk, CVE-2026-20127 carries a CVSS score of 10.0 - the maximum possible severity rating. The root cause is a broken peering authentication mechanism (CWE-287: Improper Authentication) in the SD-WAN control plane. An unauthenticated remote attacker can send crafted requests to an affected system to bypass authentication entirely and log in as an internal, high-privileged non-root user account. From this foothold, attackers can access NETCONF Cisco's network configuration protocol, enabling direct manipulation of SD-WAN fabric configuration across the entire overlay network. Cisco has confirmed no workaround is available; patching to a fixed release is the only complete remediation. The vulnerability affects both products regardless of device configuration, meaning deployment posture does not reduce exposure.

The vulnerability was originally identified and reported to Cisco by the Australian Signals Directorate's Australian Cyber Security Centre (ASD-ACSC), which simultaneously published a threat hunt guide and mitigation advisory. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 26-03 mandating Federal Civilian Executive Branch (FCEB) agencies to apply fixes within 24 hours, complete SD-WAN device inventories by February 26, and submit detailed remediation reports by March 5, 2026. CVE-2026-20127 and the related CVE-2022-20775 were simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

UAT-8616: A Sophisticated Threat Actor Exploiting This as a Zero-Day Since 2023

Cisco Talos attributes the exploitation campaign to a cluster designated UAT-8616, assessed with high confidence as a highly sophisticated threat actor. Talos researchers found forensic evidence of malicious activity dating back to at least 2023 meaning UAT-8616 possessed and weaponized this zero-day for approximately three years before public disclosure. Post-exploitation behavior follows a consistent pattern: after gaining initial access via the authentication bypass, UAT-8616 adds a rogue peer to the SD-WAN configuration, then leverages a software version downgrade exploiting CVE-2022-20775 to escalate privileges to root and establish long-term persistence within the SD-WAN environment. This chaining of vulnerabilities (CVE-2026-20127 for initial access + CVE-2022-20775 for privilege escalation) demonstrates deliberate, multi-stage tradecraft rather than opportunistic exploitation. While Cisco Talos has not publicly linked UAT-8616 to a known nation-state APT group, the three-year zero-day retention period, focus on critical infrastructure, and level of operational sophistication are consistent with a state-sponsored or state-adjacent actor.

Exploitation Now at Scale: Honeypot Telemetry and Webshell Families

Separate from the UAT-8616 campaign, the public disclosure of CVE-2026-20127 has triggered mass opportunistic exploitation. Honeypot intelligence collected by researchers at Defused Cyber through their Cisco SD-WAN honeypot intel stream confirms two distinct attacker profiles operating concurrently, identifiable by the webshell families being deployed:

The coexistence of Type 1 and Type 2 activity on the same vulnerability indicates that CVE-2026-20127 is now simultaneously being exploited by at least two distinct attacker populations: commodity actors using automation for mass access harvesting, and skilled operators deploying purpose-built, anti-forensic implants for persistent access.

Observed Attack Infrastructure: Sample IOCs

The following IP addresses have been observed in active exploitation attempts, sourced from Defused Cyber's SD-WAN honeypot telemetry. Attribution of ASN and organization is provided for defensive context Tor exit node and cloud hosting IPs are commonly used for source anonymization and should not be treated as indicative of the operator's actual geographic location:

The geographic and ASN diversity of observed source IPs spanning Tor exit infrastructure, Chinese cloud providers, and anonymous VPS hosting across four continents is consistent with a distributed botnet or coordinated multi-operator campaign using disposable or obfuscated attack infrastructure. The presence of multiple Chinese ASN-sourced IPs is noted, though attribution of exploitation to a specific actor based solely on source IP is assessed as unreliable given the prevalence of proxy and cloud anonymization.

Affected Versions and Patch Guidance

CVE-2026-20127 affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. Fixed releases are available for the following versions:

Cisco notes that versions 20.11, 20.13, 20.14, 20.16, and versions prior to 20.9 have reached End of Software Maintenance and customers must migrate to a supported release. As there is no workaround, organizations running internet-exposed SD-WAN management planes should treat patching as a P0 remediation task.

Detection and Threat Hunting Guidance

For organizations that have not yet patched or that patched without first assessing for prior compromise the following detection steps are recommended based on Cisco Talos and ASD-ACSC guidance:

Intelligence Assessment

CVE-2026-20127 presents a threat profile of exceptional severity along multiple dimensions simultaneously: a CVSS 10.0 score, confirmed zero-day exploitation dating to 2023 by a sophisticated actor, no available workaround, and now mass opportunistic exploitation following public PoC release. The appearance of Behinder-style in-memory implants with AES-encrypted C2 within days of public disclosure strongly suggests that at least one sophisticated actor beyond UAT-8616 had pre-positioned tooling for this vulnerability or rapidly adapted existing SD-WAN exploitation frameworks. IntelFusions assesses with high confidence that organizations with internet-exposed Cisco Catalyst SD-WAN management planes that have not yet patched should treat themselves as potentially compromised and initiate forensic review in parallel with patching, rather than treating patch application as sufficient remediation on its own. The long exploitation window (2023–2026) means that UAT-8616-attributed compromise may have persisted undetected for years in some environments.

This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. IOCs are sourced from public honeypot telemetry and should be validated before operational use. Claims described herein have not been independently verified unless explicitly stated.

Read the full analysis on IntelFusions