Executive Summary
In February 2026, authorities disclosed that since 2023, attackers have been exploiting two zero-day vulnerabilities in Cisco's network edge software. The threat actor, identified as UAT-8616, utilized CVE-2026-20127 to bypass authentication and subsequently downgraded the software to exploit CVE-2022-20775, achieving root access. This sophisticated campaign targeted critical infrastructure sectors, establishing persistent footholds without detection.
This incident underscores a growing trend of targeting network edge devices to gain long-term access to high-value organizations. The prolonged undetected exploitation highlights the need for enhanced monitoring and rapid response mechanisms to address emerging threats.
Why This Matters Now
The exploitation of these vulnerabilities over a three-year period without detection highlights the urgent need for organizations to reassess and strengthen their network security measures, particularly focusing on edge devices that are increasingly targeted by sophisticated threat actors.
Attack Path Analysis
Attackers exploited CVE-2026-20127 to bypass authentication on Cisco SD-WAN systems, gaining administrative access. They then downgraded the software to exploit CVE-2022-20775, escalating privileges to root. With root access, they moved laterally across the network, establishing persistent footholds. Command and control channels were set up to maintain access and exfiltrate data. Sensitive information was exfiltrated through these channels. The impact included unauthorized access to critical infrastructure and potential data breaches.
Kill Chain Progression
Initial Compromise
Description
Exploited CVE-2026-20127 to bypass authentication on Cisco SD-WAN systems, gaining administrative access.
Related CVEs
CVE-2026-20127
CVSS 10An authentication bypass vulnerability in Cisco's network edge software allows unauthenticated remote attackers to gain full control of the system.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – Unknown
Cisco Firepower Threat Defense (FTD) – Unknown
Exploit Status:
exploited in the wildCVE-2022-20775
CVSS 7.8Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
Affected Products:
Cisco SD-WAN Software – Unknown
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Exploitation for Defense Evasion
Valid Accounts
Protocol Tunneling
Obfuscated Files or Information
File and Directory Discovery
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal networks directly compromised by Cisco zero-day exploits requiring CISA emergency directive compliance and immediate infrastructure security assessment.
Telecommunications
Network edge infrastructure vulnerable to three-year APT campaign exploiting SD-WAN systems with potential for widespread service disruption.
Utilities
Critical infrastructure sectors targeted by sophisticated threat actors gaining persistent footholds through network edge device exploitation campaigns.
Financial Services
High-value organizations face elevated risks from APT groups exploiting network infrastructure for long-term espionage and lateral movement.
Sources
- Governments issue warning over Cisco zero-day attacks dating back to 2023https://cyberscoop.com/cisco-zero-days-cisa-emergency-directive-five-eyes/Verified
- CISA Issues Emergency Directive Requiring Federal Agencies to Identify and Mitigate Cisco Zero-Day Vulnerabilitieshttps://www.cisa.gov/news-events/news/cisa-issues-emergency-directive-requiring-federal-agencies-identify-and-mitigate-cisco-zero-dayVerified
- CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Deviceshttps://www.cisa.gov/news-events/alerts/2025/09/25/cisa-directs-federal-agencies-identify-and-mitigate-potential-compromise-cisco-devicesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to escalate privileges and move laterally, thereby reducing the overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained, potentially limiting their ability to exploit authentication vulnerabilities.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the risk of gaining root access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could have been restricted, limiting the spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels may have been detected and disrupted, reducing the attacker's ability to maintain access.
Control: Egress Security & Policy Enforcement
Mitigation: The exfiltration of sensitive data could have been limited, reducing the risk of data breaches.
The overall impact of unauthorized access and data breaches could have been reduced, limiting damage to critical infrastructure.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Services
- Firewall Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive government and critical infrastructure data due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement and enforce least privilege access.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Multicloud Visibility & Control to monitor and manage network traffic across environments.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Apply Secure Hybrid Connectivity (DCE) to ensure encrypted and resilient connections between on-premises and cloud environments.



