Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
ID: f11c5858-76ae-5ad7-9fd4-dbab500c2113
STIX ID: report--f11c5858-76ae-5ad7-9fd4-dbab500c2113
Feed Name: Bleeping Computer
Cisco disclosed a critical, actively exploited authentication bypass (CVE-2026-20127, CVSS 10.0) affecting Cisco Catalyst SD‑WAN controllers and managers; attackers have used it to add rogue peers and, in some cases, escalate to root by exploiting a related CVE (CVE‑2022‑20775) via software downgrades. Multiple advisories (Cisco, Talos, CISA, UK NCSC) provide indicators of compromise—unauthorized SSH publickey logins for vmanage-admin, unexpected peering events, unexpected root logins, unauthorized SSH keys, log tampering, software downgrades—and urgent mitigation guidance including applying vendor updates, isolating management interfaces, collecting forensic artifacts, and treating compromised devices as requiring fresh installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
