logo

U.S. CISA adds Cisco SD-WAN flaws to its Known Exploited Vulnerabilities catalog

ID: 2243b17d-d613-5976-b1a9-54fed9680223

STIX ID: report--2243b17d-d613-5976-b1a9-54fed9680223

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added two critical Cisco Catalyst SD-WAN flaws (CVE-2026-20127 — CVSS 10.0 authentication bypass — and CVE-2022-20775 — CLI privilege escalation) to its Known Exploited Vulnerabilities catalog after Cisco and Cisco Talos observed active exploitation since 2023 by a highly sophisticated actor tracked as UAT-8616; the attacker reportedly used a software downgrade plus the privilege-escalation bug to gain persistent root/admin access and manipulate SD‑WAN configurations. Cisco published patched releases and recommended immediate upgrades, log reviews for suspicious 'Accepted publickey for vmanage-admin' entries, and temporary port restrictions while urging customers to remediate vulnerable deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.