Back to Local Business

Cisco SD-WAN Systems Targeted in Ongoing Sophisticated Campaign

Security researchers have identified a prolonged series of attacks exploiting vulnerabilities in Cisco SD-WAN infrastructure, affecting government and critical sector networks.

Opal Keller

July 7, 20262 min read

Network Infrastructure Security - illustration, Jake Team LLC
Network Infrastructure Security - illustration, Jake Team LLC

A sustained campaign targeting Cisco SD-WAN systems has been tracked by security experts since the beginning of 2026, raising concerns about the security of critical network infrastructure. The attacks have reportedly impacted key government sites and providers of essential services, prompting heightened anxiety among authorities worldwide.

The Cybersecurity and Infrastructure Security Agency issued an emergency directive in February warning of a threat actor exploiting an authentication bypass vulnerability, identified as CVE-2026-20127, and a privilege-escalation flaw, CVE-2026-20775, within Cisco Catalyst SD-WAN systems. Later in May, Cisco Talos researchers reported that a sophisticated group known as UAT-8616 was actively targeting another authentication bypass flaw, CVE-2026-20182.

Additional threats involved a different actor chaining three vulnerabilities in the Cisco Catalyst SD-WAN Manager. These flaws, designated CVE-2026-20133, CVE-2026-20122, and CVE-2026-20128, allowed attackers to gain device access and deploy web shells capable of executing bash commands. This follows a 2024 campaign by the China-nexus group Salt Typhoon, which used access to Cisco devices to infiltrate major telecommunications providers.

Cisco remains a dominant provider of secure networking equipment for businesses and governments, with approximately 39 million devices connected to its platform and one billion monthly clients. The company observes 750 billion security events daily. However, this widespread adoption makes Cisco environments high-value targets for state-nexus and other advanced threat actors.

Douglas McKee, director of vulnerability intelligence at Rapid7, noted that edge infrastructure is a primary target in enterprise security. Compromising SD-WAN or firewall management grants attackers control over policy, visibility, routing, and segmentation across large network segments. Jonathan Forest, a VP analyst at Gartner, added that the extensive use of Cisco products in sensitive networks makes them frequent targets.

Because Cisco Catalyst SD-WAN is often implemented within a customer’s own environment, security teams are primarily responsible for patching their software. Forest stated that this structure can lead to delays in applying patches, leaving vulnerabilities exposed for extended periods and increasing the window of opportunity for attackers.

Cisco employs about 2,000 people in Richardson, according to local government records.

Source: Cybersecurity Dive.

Sources

https://www.cybersecuritydive.com/news/sophisticated-threat-campaign-pushes-cisco-to-the-very-edge/824569/

Share

Opal Keller

Opal Keller reports on local business, new openings, and economic development in Richardson.

Related Stories

More in Richardson