logo

Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation

ID: 7be1a636-13f3-56a4-b7dc-99af30132753

STIX ID: report--7be1a636-13f3-56a4-b7dc-99af30132753

Feed Name: Sophos Blogs

Threat Score
85/100

Date Published: 2026-02-26

Date Updated: 2026-04-30

...
...

On February 25, 2026, CISA and the UK NCSC warned that two Cisco SD‑WAN vulnerabilities (CVE-2026-20127 — remote auth bypass enabling admin access; CVE-2022-20775 — local privilege escalation) are being actively exploited against federal networks; CISA issued an emergency directive and vendors (including Cisco and Sophos) provided mitigations and detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.