logo

CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws

ID: 3044d5d7-d3bf-5c9f-9061-147245fa211e

STIX ID: report--3044d5d7-d3bf-5c9f-9061-147245fa211e

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-22

...
...

CISA issued Emergency Directive 26-03 warning of active exploitation of CVE-2026-20127 — a critical (CVSS 10) authentication bypass in Cisco Catalyst SD‑WAN — and ordered federal agencies to identify affected systems, store and submit logs and forensic artifacts to CISA’s Cloud Logging Aggregation Warehouse, apply vendor patches, hunt for evidence of compromise, rebuild systems if root access is found, and report remediation by set deadlines as investigators work to determine the scope of exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.