UAT-8616 is a highly sophisticated threat cluster tracked by Cisco Talos for sustained exploitation of Cisco Catalyst SD-WAN control-plane infrastructure since at least 2023. Cisco has attributed exploitation of the authentication-bypass vulnerabilities CVE-2026-20127 and CVE-2026-20182 to the cluster with high confidence. The actor has targeted critical-infrastructure sectors and demonstrated detailed knowledge of SD-WAN peering and management-plane functions. UAT-8616 obtains unauthorized privileged access by abusing weaknesses in SD-WAN peering authentication, enabling it to establish rogue peer relationships and access administrative control-plane functions. Observed post-compromise activity includes adding SSH keys for persistent access, manipulating NETCONF configuration, and attempting root-level privilege escalation. In prior intrusions, the actor downgraded software to exploit CVE-2022-20775 for root access, then restored the original software version. It has also created a concealed UID 0 account and restored altered system-account files after use. These actions, together with configuration reversion, log clearing, deletion of malicious artifacts, and validation that evidence had been removed, demonstrate deliberate anti-forensic tradecraft. Compromise of an SD-WAN Controller or Manager can permit manipulation of routing, policy, and other configuration across managed SD-WAN infrastructure. Cisco has reported that infrastructure associated with UAT-8616 overlaps with Operational Relay Box networks that have been associated with China-nexus espionage activity. However, UAT-8616 has not been formally attributed to a specific country or publicly identified organization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Cisco Talos tracks the threat actor behind the attacks as UAT-8616, which they previously linked to attacks targeting another zero-day vulnerability impacting Cisco Catalyst SD-Wan Controller, CVE-2026-20127 (CVSS: 10), in February 2026.
Cisco said at the time that attackers could exploit CVE-2026-20127 to gain admin rights, access NETCONF, and reconfigure the SD-WAN fabric, before exploiting CVE-2022-20775 (7.8), a path traversal flaw discovered in September 2022, to gain root access.
On May 14th, 2026, Cisco disclosed a maximum severity vulnerability in Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) Controller and SD-WAN Manager. The vulnerability, tracked as CVE-2026-20182 (CVSS: 10) allows a remote, unauthenticated attacker to bypass authentication and gain administrative privileges on affected systems. Cisco Talos has confirmed real-world exploitation occurred prior to the release of security patches.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
2 more CVEs tied to this actor tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign targeting Cisco Catalyst SD-WAN Manager (vManage) by chaining authentication bypass vulnerabilities for initial access, then escalating privileges to root, creating a hidden UID 0 account, modifying configurations on edge devices, and using anti-forensic cleanup to remove traces.
Exploiting Cisco SD-WAN Controller authentication bypass vulnerability CVE-2026-20127 in attacks since at least 2023.
A sophisticated threat cluster attributed by Cisco Talos to exploitation of Cisco SD-WAN vulnerabilities, with activity dating to at least 2023 and a history of targeting critical infrastructure sectors.
Attributed with exploiting some actively exploited Cisco SD-WAN vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.