A highly sophisticated cyber espionage campaign has been uncovered exploiting a previously unknown vulnerability in Cisco’s widely used SD-WAN infrastructure, raising serious concerns long-term, undetected access to critical networks worldwide.
Security researchers and government agencies have confirmed that attackers have been leveraging the flaw—tracked as CVE-2026-20127 —since at least 2023, targeting organizations that rely on Cisco Catalyst SD-WAN Controller (formerly known as vSmart) to manage network traffic across distributed environments.
The vulnerability, described as an authentication bypass flaw, was initially reported by the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC). According to officials, attackers were able to exploit weaknesses in the SD-WAN peering authentication mechanism to infiltrate networks at a foundational level.
Once inside, the threat actor added rogue devices to the network, enabling deeper access and eventual control.
Cisco explained in its advisory that the flaw stems from improperly functioning authentication controls within the system. By sending specially crafted requests, an attacker could gain access as a high-privileged internal user—without needing valid credentials.
This access, while not immediately root-level, is particularly dangerous. It allows attackers to interact with NETCONF , a protocol used to configure and manage network devices. Through this channel, malicious actors could manipulate network configurations, reroute traffic, or create hidden backdoors.
Further investigation by Cisco’s Talos threat intelligence team revealed that the attackers did not stop at initial access. The group—tracked under the name “UAT-8616” —demonstrated advanced post-compromise techniques to escalate privileges and maintain persistence.
According to Talos, the attackers likely:
Downgraded the system software to an older, vulnerable version Exploited a previously known flaw ( CVE-2022-20775 ) to gain root access Restored the system back to its original version to avoid detection
This method allowed them to achieve full administrative control while leaving minimal traces, a hallmark of advanced persistent threat (APT) activity.
This level of operational sophistication indicates a well-resourced actor, potentially with nation-state backing.
This campaign reflects a broader and accelerating trend: attackers are increasingly targeting network edge devices such as routers, firewalls, and SD-WAN controllers.
These systems are particularly attractive because:
They sit at the boundary of enterprise networks They often lack robust monitoring compared to endpoints Compromise can grant visibility into—and control over—entire network environments
Talos noted that UAT-8616’s activity aligns with ongoing efforts by threat actors to establish persistent footholds in high-value targets , including organizations in critical infrastructure sectors such as energy, telecommunications, and government.
The discovery has triggered a coordinated response among cybersecurity agencies worldwide.
The Australian Cyber Security Centre has released detailed mitigation guidance along with a threat hunting playbook to help organizations detect signs of compromise.
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive addressing what it described as a “significant cyber threat” affecting federal networks.
Federal agencies have been instructed to act immediately by:
Identifying all Cisco SD-WAN systems in use Collecting system snapshots and logs for forensic analysis Applying patches without delay Conducting threat hunting for indicators of compromise Implementing security measures outlined in Cisco’s hardening guidelines
Cisco and its partners are urging all affected organizations to take immediate action, emphasizing that exploitation has already been active in the wild for years.
Recommended steps include:
Reviewing logs for unauthorized peer connections Investigating unusual configuration changes Validating the integrity of SD-WAN devices Applying patches and security updates as soon as possible
Given the stealthy nature of the attack and the potential for long-term persistence, experts warn that simply patching systems may not be sufficient—comprehensive forensic analysis may be required to fully eradicate attacker access.
The revelation that attackers may have maintained undetected access to core networking infrastructure for years underscores a critical challenge facing modern cybersecurity: visibility into the systems that underpin digital operations.
As organizations continue to adopt SD-WAN and other edge technologies, the incident serves as a stark reminder that these platforms—while powerful—can also become high-impact targets if not properly secured.
Similar vulnerabilities may remain undiscovered in other network technologies, making proactive monitoring, rapid patching, and zero-trust principles more important than ever.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
