logo

Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023

ID: f11c5858-76ae-5ad7-9fd4-dbab500c2113

STIX ID: report--f11c5858-76ae-5ad7-9fd4-dbab500c2113

Feed Name: Bleeping Computer

Threat Score
95/100

Date Published: 2026-02-25

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Cisco disclosed a critical, actively exploited authentication bypass (CVE-2026-20127, CVSS 10.0) affecting Cisco Catalyst SD‑WAN controllers and managers; attackers have used it to add rogue peers and, in some cases, escalate to root by exploiting a related CVE (CVE‑2022‑20775) via software downgrades. Multiple advisories (Cisco, Talos, CISA, UK NCSC) provide indicators of compromise—unauthorized SSH publickey logins for vmanage-admin, unexpected peering events, unexpected root logins, unauthorized SSH keys, log tampering, software downgrades—and urgent mitigation guidance including applying vendor updates, isolating management interfaces, collecting forensic artifacts, and treating compromised devices as requiring fresh installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.