CYBERSECURITY & PRIVACY — 2026-03-16
Cisco Catalyst SD-WAN Zero-Day (CVSS 10) Exploited by Sophisticated Threat Actor
CVE-2026-20127, a maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller and Manager, allows remote attackers to gain administrative privileges. Cisco Talos attributed the exploitation to UAT-8616, a 'highly sophisticated' actor active since at least 2023. The vulnerability targets enterprise network management infrastructure, a high-value target for supply chain compromise and lateral movement across managed networks.