Cisco Talos and Five Eyes cybersecurity agencies are warning about threat actor UAT-8616, which has been exploiting a zero-day vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controllers since at least 2023. The attack chains an authentication bypass flaw with a path traversal vulnerability (CVE-2022-20775) by downgrading the device to an older, vulnerable software version to gain root access, then restoring the original version to evade detection. CISA has ordered federal agencies to inventory and patch affected systems. A 40-page Hunt Guide was released by Five Eyes agencies to help organizations detect and remediate the threat. Experts warn the attack's sophistication lies in chaining vulnerabilities to achieve persistent root access across the entire SD-WAN fabric, enabling manipulation of routing, segmentation, and configuration network-wide.