logo

CVE-2026-20127: Cisco SD-WAN Zero-Day Exploited Since 2023

ID: c805ea97-d5de-5e5c-a9c1-a8f05eaa3dd3

STIX ID: report--c805ea97-d5de-5e5c-a9c1-a8f05eaa3dd3

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

CVE-2026-20127 is a critical authentication bypass in Cisco Catalyst SD‑WAN Controller and Manager that is being actively exploited (tracked by Cisco Talos as UAT-8616). Exploitation can grant administrative control of the SD‑WAN control plane—allowing attackers to add rogue peers, manipulate NETCONF, escalate to root, persist via version downgrade/restore chains—and has triggered a CISA Emergency Directive; Cisco recommends upgrading to fixed releases, restricting exposure, auditing logs, and engaging TAC if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.