Global Attack on Cisco Corporate Networks: What We Know and How to Protect Yourself

Introduction

In recent years, corporate networks have become increasingly frequent targets of sophisticated cyberattacks. When the infrastructures that manage network traffic on a global scale are hit, the consequences can affect organizations of every sector and size. This is exactly the scenario unfolding with the vulnerability discovered in Cisco Catalyst SD-WAN systems.

What Happened

Starting on February 25, 2026, cybersecurity government agencies from several countries, including CISA (United States), NSA (United States), NCSC-UK (United Kingdom), and NCSC-NZ (New Zealand), issued a joint advisory regarding the active exploitation of a vulnerability identified as CVE-2026-20127. This vulnerability affects two widely used Cisco products in corporate networks: the Catalyst SD-WAN Controller and the Catalyst SD-WAN Manager. In simple terms, these systems are responsible for managing and coordinating network traffic between different locations within the same organization, such as offices, branches, or data centers.

The vulnerability allows an attacker to bypass authentication mechanisms — that is, to gain access to the system without possessing the correct credentials. Cisco Talos experts have identified and monitored the group responsible for the intrusions under the designation UAT-8616. Once access is obtained, the attackers add a so-called unauthorized peer to the network, a technique that allows them to acquire the highest privileges on the system (root access) and maintain a stable, long-lasting presence within the compromised infrastructure, even over time.

Why It Matters and What the Potential Impact Is

The most concerning aspect of this situation is its global scope: the joint advisory reports that the malicious activity involves organizations worldwide that are using the vulnerable systems. No specific victim names have been made public. However, those using these Cisco products without having applied the appropriate countermeasures may have already been compromised without knowing it. Unauthorized root access theoretically allows reading, modifying, or exfiltrating data, as well as altering the functioning of the network.

What Companies and Users Can Do Now

Organizations using Cisco Catalyst SD-WAN Controller or Manager must immediately consult the official security advisory published by Cisco and apply the indicated patches or mitigations. It is also advisable to review system logs to detect any anomalous activity and to contact their internal cybersecurity team or a specialized provider. Those without internal resources can refer to the public advisories from the agencies mentioned, which also include guidance for searching for traces of compromise.

Final Takeaways

  • A vulnerability in network management systems can give an attacker complete control over the corporate infrastructure, without the need to steal passwords.
  • The alert was issued simultaneously by multiple government agencies, indicating a threat considered serious and widespread at an international level.
  • Updating systems promptly and monitoring networks are the most effective actions to reduce risk.

Sources:
https://www.ncsc.govt.nz/alerts/exploitation-of-cisco-sd-wan-appliances/
https://www.ncsc.gov.uk/news/exploitation-cisco-catalyst-sd-wans
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
https://blog.talosintelligence.com/uat-8616-sd-wan/

Source: CISA Advisories