UAT-8616 is a highly sophisticated threat actor cluster tracked by Cisco Talos. Cisco attributes exploitation activity against Cisco Catalyst SD-WAN infrastructure to this actor with high confidence, with activity dating back to at least 2023. The group has been linked to zero-day exploitation of the authentication bypass vulnerabilities CVE-2026-20127 and CVE-2026-20182 to gain unauthorized administrative access to Cisco SD-WAN systems, including by creating rogue peers through the peering authentication mechanism. Reported post-compromise actions include adding SSH keys, modifying NETCONF configurations, escalating privileges to root, and in previously detected attacks downgrading software versions to exploit CVE-2022-20775 for root access before restoring the original version. Reporting also describes a reconstructed intrusion chain involving unauthorized peering, SSH access as vmanage-admin, use of CVE-2026-20245 for root compromise, creation of a hidden UID 0 account, and anti-forensic restoration of modified system files. Cisco says the actor targets critical infrastructure sectors. Multiple reports describe overlap between infrastructure used by UAT-8616 and Operational Relay Box networks; some reporting characterizes the actor as alleged China-nexus, but the content also states UAT-8616 has not been formally attributed to a specific country or named group. Known alias in the provided content: uat_8616.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
CVE-2026-20127: обход аутентификации пиринга. Уязвимость в механизме peering authentication затрагивает все три контрольных компонента: SD-WAN Controller, Manager и Validator. Некорректная аутентификация пиринга позволяет неаутентифицированному удалённому атакующему обойти проверку подлинности и получить административные привилегии.
Cisco said at the time that attackers could exploit CVE-2026-20127 to gain admin rights, access NETCONF, and reconfigure the SD-WAN fabric, before exploiting CVE-2022-20775 (7.8), a path traversal flaw discovered in September 2022, to gain root access.
CVE-2026-20182: второй bypass в том же сервисе. Это отдельная проблема в том же участке сетевого стека — сервисе vdaemon через DTLS, но в процедуре handshaking контрольных соединений. Cisco наблюдала эксплуатацию этой SD-WAN vManage уязвимости как zero-day в мае 2026.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
2 more CVEs tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign targeting Cisco Catalyst SD-WAN Manager (vManage) by chaining authentication bypass vulnerabilities for initial access, then escalating privileges to root, creating a hidden UID 0 account, modifying configurations on edge devices, and using anti-forensic cleanup to remove traces.
Exploiting Cisco SD-WAN Controller authentication bypass vulnerability CVE-2026-20127 in attacks since at least 2023.
A sophisticated threat cluster attributed by Cisco Talos to exploitation of Cisco SD-WAN vulnerabilities, with activity dating to at least 2023 and a history of targeting critical infrastructure sectors.
Attributed with exploiting some actively exploited Cisco SD-WAN vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.