UAT-8616 is a highly sophisticated threat cluster associated with long-running exploitation of Cisco Catalyst SD-WAN infrastructure since at least 2023. The actor has been linked with high confidence to zero-day exploitation of critical authentication bypass vulnerabilities in Cisco SD-WAN control-plane components, notably CVE-2026-20127 and CVE-2026-20182, to establish unauthorized peering relationships and obtain high-privileged administrative access to SD-WAN controllers and managers. Post-compromise activity has included adding SSH keys for persistent access, modifying NETCONF configurations to manipulate the SD-WAN fabric, escalating privileges to root, and in some cases pushing configuration changes to downstream edge devices. Observed intrusion chains show deep platform knowledge and deliberate operational security. UAT-8616 has used software downgrade techniques to expose and exploit CVE-2022-20775 for root escalation after initial access, and has also been associated with exploitation paths involving CVE-2026-20245 to execute commands as root from an already privileged position. Reported tradecraft includes creation of a hidden UID 0 root account, restoration of modified system files after use, deletion of malicious artifacts, reversion of configuration changes, and validation steps intended to confirm that forensic evidence was removed. These behaviors indicate strong anti-forensic discipline and an emphasis on stealth and persistence in network-management environments. The actor has targeted Cisco SD-WAN management and control infrastructure, including controllers, managers, and validator-related peering functions, with strategic risk extending across entire managed overlays because compromise of a centralized SD-WAN control plane can enable broad reconfiguration of routing, policy, access control, VPN, and related network services. UAT-8616 has been described as targeting critical infrastructure sectors. Public reporting has noted overlap between infrastructure used by UAT-8616 and Operational Relay Box networks that have been associated with China-nexus espionage activity. However, formal public attribution to a specific state or named intrusion set remains limited. No corroborated sub-groups are established beyond the cluster designation UAT-8616.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
CVE-2026-20127: обход аутентификации пиринга. Уязвимость в механизме peering authentication затрагивает все три контрольных компонента: SD-WAN Controller, Manager и Validator. Некорректная аутентификация пиринга позволяет неаутентифицированному удалённому атакующему обойти проверку подлинности и получить административные привилегии.
Cisco said at the time that attackers could exploit CVE-2026-20127 to gain admin rights, access NETCONF, and reconfigure the SD-WAN fabric, before exploiting CVE-2022-20775 (7.8), a path traversal flaw discovered in September 2022, to gain root access.
CVE-2026-20182: второй bypass в том же сервисе. Это отдельная проблема в том же участке сетевого стека — сервисе vdaemon через DTLS, но в процедуре handshaking контрольных соединений. Cisco наблюдала эксплуатацию этой SD-WAN vManage уязвимости как zero-day в мае 2026.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
2 more CVEs tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign targeting Cisco Catalyst SD-WAN Manager (vManage) by chaining authentication bypass vulnerabilities for initial access, then escalating privileges to root, creating a hidden UID 0 account, modifying configurations on edge devices, and using anti-forensic cleanup to remove traces.
Exploiting Cisco SD-WAN Controller authentication bypass vulnerability CVE-2026-20127 in attacks since at least 2023.
A sophisticated threat cluster attributed by Cisco Talos to exploitation of Cisco SD-WAN vulnerabilities, with activity dating to at least 2023 and a history of targeting critical infrastructure sectors.
Attributed with exploiting some actively exploited Cisco SD-WAN vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.