Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited
    Cybersecurity

    Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited

    adminBy adminMarch 8, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Cisco vulnerability patches
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Exposure management company WatchTowr reports that a recent Cisco Catalyst SD-WAN vulnerability, initially exploited as a zero-day, is now being used more frequently by threat actors.

    The in-the-wild exploitation of four Cisco Catalyst SD-WAN vulnerabilities came to light in recent weeks. One of them is CVE-2026-20127, which had been exploited as a zero-day in combination with an older vulnerability, CVE-2022-20775, to bypass authentication, escalate privileges, and establish persistence on systems.

    Cisco Talos linked the attacks to UAT-8616, a highly sophisticated threat actor of unspecified origin and motivation that has been active since at least 2023. 

    WatchTowr’s head of proactive threat intelligence, Ryan Dewhurst, told SecurityWeek that the pace of exploitation for CVE-2026-20127 has — unsurprisingly — escalated quickly.

    “This is no longer targeted activity that was described previously, but now internet-wide and growing,” Dewhurst said.

    “In total, the watchTowr proactive threat intelligence team has seen exploitation attempts from numerous unique IP addresses and observed threat actors deploying webshells,” he explained. “The largest spike in activity occurred on March 4, with attacks widely spread across various regions worldwide, and U.S.-based areas saw slightly higher activity than others.” 

    Advertisement. Scroll to continue reading.

    The expert warned, “We expect activity to continue as part of the typical long tail of exploitation, as more threat actors become involved,” adding, “With mass and opportunistic exploitation at play, any exposed system should be considered compromised until proven otherwise.”

    Cisco this week updated a February 25 advisory to inform customers about the exploitation of two additional Catalyst SD-WAN vulnerabilities, which can be exploited by authenticated attackers for privilege escalation: CVE-2026-20128 and CVE-2026-20122.

    The company has not shared any details on the attacks exploiting these vulnerabilities, but its description indicates they have been chained with other flaws.

    It’s unclear if the same threat actor is behind all of the campaigns targeting Catalyst SD-WAN vulnerabilities. Cisco recently warned that a zero-day in Secure Email Gateway appliances had been exploited by China-linked hackers, but again, it’s unclear if the attacks are in any way related. 

    Related: China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

    Related: Cisco Patches Critical Vulnerabilities in Enterprise Networking Products

    Related: Cisco, F5 Patch High-Severity Vulnerabilities

    Catalyst Cisco Exploited SDWAN vulnerability Widely
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to get over “printer’s block” and get more out of your 3D printer
    Next Article How to Track Your Sleep With an Apple Watch
    admin
    • Website

    Related Posts

    Attackers exploiting unpatched Cisco SD-WAN flaw

    June 9, 2026

    How Cisco IT cut observability costs by 86% and eliminated major network outages

    June 5, 2026

    What is Cisco Cloud Control and why should customers care?

    June 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Search Sends 23% Of Queries To The Open Web

    June 10, 2026

    Residential proxies are hiding in plain sight inside enterprise networks

    June 10, 2026

    How to Advertise on Facebook in 8 Steps: The Visual Guide

    June 10, 2026

    How Taegan Goddard Turned Political Wire’s 4 to 5 Million Monthly Visitors Into a Subscription Opportunity

    June 10, 2026
    Categories
    • Blogging (92)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (249)
    • SEO & Digital Marketing (1,436)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (344)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Search Sends 23% Of Queries To The Open Web

    June 10, 2026

    Residential proxies are hiding in plain sight inside enterprise networks

    June 10, 2026

    How to Advertise on Facebook in 8 Steps: The Visual Guide

    June 10, 2026
    Most Popular
    • Google Search Sends 23% Of Queries To The Open Web
    • Residential proxies are hiding in plain sight inside enterprise networks
    • How to Advertise on Facebook in 8 Steps: The Visual Guide
    • How Taegan Goddard Turned Political Wire’s 4 to 5 Million Monthly Visitors Into a Subscription Opportunity
    • How to make prompt tracking much more accurate
    • Claude Is The Fastest-Growing AI Traffic Source, Per New Data
    • OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campus
    • How to Find and Fix Orphan Pages That Are Killing Your WordPress SEO
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.