Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation
ID: 7be1a636-13f3-56a4-b7dc-99af30132753
STIX ID: report--7be1a636-13f3-56a4-b7dc-99af30132753
Feed Name: Sophos Blogs
Threat Score
On February 25, 2026, CISA and the UK NCSC warned that two Cisco SD‑WAN vulnerabilities (CVE-2026-20127 — remote auth bypass enabling admin access; CVE-2022-20775 — local privilege escalation) are being actively exploited against federal networks; CISA issued an emergency directive and vendors (including Cisco and Sophos) provided mitigations and detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
