Vulnerabilities & Exploits · Zero-Day Exploit
Cisco SD‑WAN Controllers Targeted by Long‑Running Zero‑Day Exploit UAT‑8616 has exploited a zero‑day in Cisco Catalyst SD‑WAN Controller and Manager since 2023. The flaw is an unauthenticated authentication‑bypass tracked as CVE‑2026‑20127 and rated CVSS 10.0.
1 source · Mar 9
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).
CISA federal remediation date Feb 27 · date passed
Timeline Sources Mar 9 The Hacker News
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
original Mar 2 The Hacker News
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-02
Every edition of this story: Cisco SD‑WAN Controllers Targeted by Long‑Running Zero‑Day Exploit
More from today
Vulnerabilities & Exploits · Zero-Day Exploit
Cisco SD‑WAN Controllers Targeted by Long‑Running Zero‑Day Exploit UAT‑8616 has exploited a zero‑day in Cisco Catalyst SD‑WAN Controller and Manager since 2023. The flaw is an unauthenticated authentication‑bypass tracked as CVE‑2026‑20127 and rated CVSS 10.0.
1 source · Mar 9
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).
CISA federal remediation date Feb 27 · date passed
Timeline Sources Mar 9 The Hacker News
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
original Mar 2 The Hacker News
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-02
Every edition of this story: Cisco SD‑WAN Controllers Targeted by Long‑Running Zero‑Day Exploit
More from today