CVE-2026-20127 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability.md
ID: 7ebd5f1a-0e7d-5ac5-a40f-f6ac319d79ae
STIX ID: report--7ebd5f1a-0e7d-5ac5-a40f-f6ac319d79ae
Feed Name: Kudelski Security
A critical unauthenticated remote vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller/Manager allows attackers to bypass peering authentication and gain administrative NETCONF access; when chained with CVE-2022-20775 (and via version downgrade) attackers can escalate to root and fully compromise devices. Cisco has published fixed releases for affected versions and recommends upgrading, network segmentation, strict access controls, and monitoring for unauthorized NETCONF activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
