Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Cisco Catalyst SD-WAN under siege: UAT-8616 actively exploits vulnerabilities

Feb 26, 2026 | Threat Intelligence Research

Cisco Catalyst SD-WAN Exploitation Threat Report

TL;DR
Cisco Talos reports an ongoing exploitation of CVE-2026-20127 affecting the Cisco Catalyst SD-WAN Controller, allowing unauthorized remote access. This campaign, tracked as UAT-8616, is attributed to a sophisticated threat actor targeting critical infrastructure.

Main Analysis
Cisco Talos has identified active exploitation of a critical vulnerability (CVE-2026-20127) within the Cisco Catalyst SD-WAN Controller, enabling unauthenticated attackers to bypass authentication and secure administrative privileges. The vulnerability is exploited through a crafted request, allowing attackers to operate as a high-privileged user. The threat actor behind this campaign, designated UAT-8616, exhibits advanced techniques, including reverting software versions to exploit an additional vulnerability (CVE-2022-20775) to gain root access.

Analysis reveals that this exploitation trend has persisted for at least three years, with attackers consistently targeting network edge devices to establish footholds within high-value organizations, particularly in critical infrastructure sectors. Such activities highlight a strategic focus on vulnerable entry points that facilitate deeper penetration into networks and systems.

Cisco Talos urges vigilance, particularly in scrutinizing peering events within Cisco Catalyst SD-WAN logs, which are essential for detecting initial unauthorized access attempts through CVE-2026-20127. Given the sophisticated nature of UAT-8616’s actions, organizations may be at risk even if attacks appear superficially normal, thus emphasizing the necessity for a meticulous review of control connection activities.

Defensive Context
Organizations using Cisco Catalyst SD-WAN technology should prioritize an analysis of their environment to identify potential indicators of compromise as outlined in the report. Specifically, those in sectors related to critical infrastructure should be particularly attentive, as they may be disproportionately targeted. Conversely, smaller businesses or those without reliance on Cisco’s SD-WAN solutions may find this threat less relevant.

Why This Matters
The risk presented by UAT-8616 is high, given its targeting of network devices that serve as critical points of access and control. Organizations that utilize Cisco SD-WAN solutions, particularly in sensitive or critical sectors, should take special heed as the vulnerability can lead to significant exploitation potential if left unaddressed.

Defender Considerations
While specific mitigation steps are not delineated, organizations should enforce strict log validation protocols. They must examine control connection events and verify the legitimacy of peering attempts against operational records. Such diligence will help identify unauthorized access attempts, particularly those indicative of exploitation from UAT-8616.

Indicators of Compromise (IOCs)

  • CVE-2026-20127
  • CVE-2022-20775
  • Malicious user account activity
  • Log entries indicative of unauthorized SSH key access and interactions
  • Anomalies in peering connections such as those from unrecognized IP addresses or abnormal operational timestamps

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles