A sustained campaign targeting Cisco SD-WAN systems has been tracked by security experts since the beginning of 2026, raising concerns about the security of critical network infrastructure. The attacks have reportedly impacted key government sites and providers of essential services, prompting heightened anxiety among authorities worldwide.
The Cybersecurity and Infrastructure Security Agency issued an emergency directive in February warning of a threat actor exploiting an authentication bypass vulnerability, identified as CVE-2026-20127, and a privilege-escalation flaw, CVE-2026-20775, within Cisco Catalyst SD-WAN systems. Later in May, Cisco Talos researchers reported that a sophisticated group known as UAT-8616 was actively targeting another authentication bypass flaw, CVE-2026-20182.
Additional threats involved a different actor chaining three vulnerabilities in the Cisco Catalyst SD-WAN Manager. These flaws, designated CVE-2026-20133, CVE-2026-20122, and CVE-2026-20128, allowed attackers to gain device access and deploy web shells capable of executing bash commands. This follows a 2024 campaign by the China-nexus group Salt Typhoon, which used access to Cisco devices to infiltrate major telecommunications providers.
Cisco remains a dominant provider of secure networking equipment for businesses and governments, with approximately 39 million devices connected to its platform and one billion monthly clients. The company observes 750 billion security events daily. However, this widespread adoption makes Cisco environments high-value targets for state-nexus and other advanced threat actors.
Douglas McKee, director of vulnerability intelligence at Rapid7, noted that edge infrastructure is a primary target in enterprise security. Compromising SD-WAN or firewall management grants attackers control over policy, visibility, routing, and segmentation across large network segments. Jonathan Forest, a VP analyst at Gartner, added that the extensive use of Cisco products in sensitive networks makes them frequent targets.
