UAT-8616 is a highly sophisticated threat cluster tracked for long-running exploitation of Cisco Catalyst SD-WAN infrastructure since at least 2023. The actor has been linked with high confidence to exploitation of critical authentication-bypass vulnerabilities in Cisco SD-WAN control-plane components, notably CVE-2026-20127 and CVE-2026-20182, to obtain unauthorized administrative access to SD-WAN Controller and Manager environments. Post-compromise activity attributed to UAT-8616 includes establishing rogue peering relationships, adding SSH keys for persistent access, modifying NETCONF configurations, escalating privileges to root, and in earlier observed intrusions downgrading software to expose and exploit CVE-2022-20775 before restoring the original version to reduce forensic visibility. Reporting also describes anti-forensic behavior such as reverting configuration changes, deleting malicious artifacts, restoring modified system files, and validating removal of indicators. In limited confirmed cases, exploitation resulted in configuration changes being pushed from the SD-WAN management plane to edge devices, highlighting the strategic impact of compromising centralized network orchestration. The actor is described as targeting critical infrastructure sectors. Cisco researchers have noted overlap between infrastructure used by UAT-8616 and Operational Relay Box networks, and some reporting characterizes the cluster as China-nexus, but no formal public attribution to a specific state or named intrusion set is established in the available facts. Known aliases are limited to UAT-8616.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Cisco Talos tracks the threat actor behind the attacks as UAT-8616, which they previously linked to attacks targeting another zero-day vulnerability impacting Cisco Catalyst SD-Wan Controller, CVE-2026-20127 (CVSS: 10), in February 2026.
Cisco said at the time that attackers could exploit CVE-2026-20127 to gain admin rights, access NETCONF, and reconfigure the SD-WAN fabric, before exploiting CVE-2022-20775 (7.8), a path traversal flaw discovered in September 2022, to gain root access.
On May 14th, 2026, Cisco disclosed a maximum severity vulnerability in Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) Controller and SD-WAN Manager. The vulnerability, tracked as CVE-2026-20182 (CVSS: 10) allows a remote, unauthenticated attacker to bypass authentication and gain administrative privileges on affected systems. Cisco Talos has confirmed real-world exploitation occurred prior to the release of security patches.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
2 more CVEs tied to this actor tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign targeting Cisco Catalyst SD-WAN Manager (vManage) by chaining authentication bypass vulnerabilities for initial access, then escalating privileges to root, creating a hidden UID 0 account, modifying configurations on edge devices, and using anti-forensic cleanup to remove traces.
Exploiting Cisco SD-WAN Controller authentication bypass vulnerability CVE-2026-20127 in attacks since at least 2023.
A sophisticated threat cluster attributed by Cisco Talos to exploitation of Cisco SD-WAN vulnerabilities, with activity dating to at least 2023 and a history of targeting critical infrastructure sectors.
Attributed with exploiting some actively exploited Cisco SD-WAN vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.