Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited

WatchTowr reports seeing exploitation attempts for CVE-2026-20127 from numerous unique IP addresses.

Cisco vulnerability exploited

Exposure management company WatchTowr reports that a recent Cisco Catalyst SD-WAN vulnerability, initially exploited as a zero-day, is now being used more frequently by threat actors.

The in-the-wild exploitation of four Cisco Catalyst SD-WAN vulnerabilities came to light in recent weeks. One of them is CVE-2026-20127, which had been exploited as a zero-day in combination with an older vulnerability, CVE-2022-20775, to bypass authentication, escalate privileges, and establish persistence on systems.

Cisco Talos linked the attacks to UAT-8616, a highly sophisticated threat actor of unspecified origin and motivation that has been active since at least 2023. 

WatchTowr’s head of proactive threat intelligence, Ryan Dewhurst, told SecurityWeek that the pace of exploitation for CVE-2026-20127 has — unsurprisingly — escalated quickly.

“This is no longer targeted activity that was described previously, but now internet-wide and growing,” Dewhurst said.

“In total, the watchTowr proactive threat intelligence team has seen exploitation attempts from numerous unique IP addresses and observed threat actors deploying webshells,” he explained. “The largest spike in activity occurred on March 4, with attacks widely spread across various regions worldwide, and U.S.-based areas saw slightly higher activity than others.” 

Advertisement. Scroll to continue reading.

The expert warned, “We expect activity to continue as part of the typical long tail of exploitation, as more threat actors become involved,” adding, “With mass and opportunistic exploitation at play, any exposed system should be considered compromised until proven otherwise.”

Cisco this week updated a February 25 advisory to inform customers about the exploitation of two additional Catalyst SD-WAN vulnerabilities, which can be exploited by authenticated attackers for privilege escalation: CVE-2026-20128 and CVE-2026-20122.

The company has not shared any details on the attacks exploiting these vulnerabilities, but its description indicates they have been chained with other flaws.

It’s unclear if the same threat actor is behind all of the campaigns targeting Catalyst SD-WAN vulnerabilities. Cisco recently warned that a zero-day in Secure Email Gateway appliances had been exploited by China-linked hackers, but again, it’s unclear if the attacks are in any way related. 

Related: China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

Related: Cisco Patches Critical Vulnerabilities in Enterprise Networking Products

Related: Cisco, F5 Patch High-Severity Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.