---
title: "Attackers Have Been Exploiting Cisco SD-WAN Zero-Day Flaw Since 2023"
url: https://daily.dev/posts/attackers-have-been-exploiting-cisco-sd-wan-zero-day-flaw-since-2023-88cyxk8km
source_url: https://securityboulevard.com/2026/02/attackers-have-been-exploiting-cisco-sd-wan-zero-day-flaw-since-2023/
type: article
source: "Security Boulevard"
published: 2026-02-26T22:24:56.986Z
updated: 2026-02-26T22:25:42.209Z
tags: ["security", "vulnerability", "zero-day"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attackers Have Been Exploiting Cisco SD-WAN Zero-Day Flaw Since 2023

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 5 min read · 0 upvotes · 0 comments

## Summary

Cisco Talos and Five Eyes cybersecurity agencies are warning about threat actor UAT-8616, which has been exploiting a zero-day vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controllers since at least 2023. The attack chains an authentication bypass flaw with a path traversal vulnerability (CVE-2022-20775) by downgrading the device to an older, vulnerable software version to gain root access, then restoring the original version to evade detection. CISA has ordered federal agencies to inventory and patch affected systems. A 40-page Hunt Guide was released by Five Eyes agencies to help organizations detect and remediate the threat. Experts warn the attack's sophistication lies in chaining vulnerabilities to achieve persistent root access across the entire SD-WAN fabric, enabling manipulation of routing, segmentation, and configuration network-wide.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/02/attackers-have-been-exploiting-cisco-sd-wan-zero-day-flaw-since-2023/>

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/attackers-have-been-exploiting-cisco-sd-wan-zero-day-flaw-since-2023-88cyxk8km)
