Cisco has disclosed a maximum-severity authentication bypass zero-day (CVE-2026-20127, CVSS 10) in its Catalyst SD-WAN Controller that has been actively exploited for at least three years since 2023. The threat actor, tracked as UAT-8616, used the flaw to add rogue peers to SD-WAN management systems, then chained it with a

5m read time From darkreading.com
Post cover image
Table of contents
The Mystery of UAT-8616Mitigating CVE-2026-20127

Sort: