logo

Global Cyber Agencies Urge Immediate Patching of Cisco SD-WAN Zero Day

ID: 54502b5f-8a9e-5852-a713-2860bb11aa8c

STIX ID: report--54502b5f-8a9e-5852-a713-2860bb11aa8c

Feed Name: Infosecurity Magazine (News)

Threat Score
95/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

...
...

The report describes a critical, actively exploited zero-day (CVE-2026-20127) in Cisco Catalyst SD‑WAN Controller/Manager that allows unauthenticated attackers to bypass authentication, obtain high-privilege access, and manipulate NETCONF; Five Eyes agencies and CISA have issued guidance and an emergency directive to patch immediately, and investigators report attackers used a downgrade to exploit a legacy LPE (CVE-2022-20775) to escalate to root and maintain persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.