CVE-2026-20127: Cisco SD-WAN Zero-Day Exploited Since 2023
ID: c805ea97-d5de-5e5c-a9c1-a8f05eaa3dd3
STIX ID: report--c805ea97-d5de-5e5c-a9c1-a8f05eaa3dd3
Feed Name: SOC Prime Blog
CVE-2026-20127 is a critical authentication bypass in Cisco Catalyst SD‑WAN Controller and Manager that is being actively exploited (tracked by Cisco Talos as UAT-8616). Exploitation can grant administrative control of the SD‑WAN control plane—allowing attackers to add rogue peers, manipulate NETCONF, escalate to root, persist via version downgrade/restore chains—and has triggered a CISA Emergency Directive; Cisco recommends upgrading to fixed releases, restricting exposure, auditing logs, and engaging TAC if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
