A monthslong exploitation campaign targeting Cisco Catalyst SD-WAN infrastructure has compromised government agencies and critical infrastructure operators worldwide, according to reporting from Cisco Talos, Mandiant, and multiple national cybersecurity authorities. The campaign, attributed in part to a threat cluster tracked as UAT-8616, began as early as February 2026 and exploited a chain of vulnerabilities — CVE-2026-20127, CVE-2026-20182, CVE-2026-20133, CVE-2026-20122, and CVE-2026-20245 — to gain unauthenticated administrative access to SD-WAN Manager and Controller appliances, deploy web shells, and establish persistent footholds.
CVE-2026-20245, a command injection flaw in Cisco Catalyst SD-WAN Manager, Controller, and Validator, is particularly notable: Mandiant found evidence it was exploited as a zero-day as early as March 2026, a full three months before Cisco released a patch in June. Attackers in these incidents demonstrated high operational sophistication, employing anti-forensic techniques including deleting and restoring system configuration files to evade detection and hinder incident response. CISA issued an emergency directive in February 2026 — Emergency Directive 26-03 — ordering federal civilian agencies to immediately secure their Cisco SD-WAN deployments following active exploitation of CVE-2026-20127 and the legacy CVE-2022-20775 privilege escalation flaw.
Cisco has released software updates addressing all identified CVEs and strongly urges customers to upgrade to patched releases. The scope of impact extends beyond the initially reported government sites, with enterprise and telecommunications operators in multiple countries reporting similar indicators of compromise.
Sources
- Cisco Talos — SD-WAN Ongoing Exploitation
- Google GTIG — Zero-Day Exploitation in Cisco Catalyst SD-WAN Manager
- Cybersecurity Dive — Sophisticated Campaign Targets Cisco SD-WAN
- Industrial Cyber — CISA ED-26-03 Orders Federal Agencies to Secure SD-WAN
Commentary
The three-month gap between exploitation of CVE-2026-20245 and Cisco’s patch is the headline here. Sophisticated threat actors are operating inside enterprise network infrastructure for months before defenders have a patch to apply — let alone time to deploy it. SD-WAN controllers are particularly attractive targets because compromising them can provide visibility into and manipulation of network routing for an entire organization, not just a single host. The anti-forensic tradecraft observed — restoring configuration files post-attack to hide changes — is a tell for mature state-nexus operators who prioritize persistence and stealth over speed.
Organizations running Cisco Catalyst SD-WAN should treat this as active: apply all available patches immediately, perform a thorough review of SD-WAN Manager audit logs for authentication anomalies and configuration changes going back to at least January 2026, and look for web shells on internet-facing SD-WAN appliances. If you haven’t already, segment SD-WAN management interfaces off public internet access entirely. CISA’s advisories for this campaign are unusually detailed and worth reviewing in full.
