Global Cyber Agencies Urge Immediate Patching of Cisco SD-WAN Zero Day
ID: 54502b5f-8a9e-5852-a713-2860bb11aa8c
STIX ID: report--54502b5f-8a9e-5852-a713-2860bb11aa8c
Feed Name: Infosecurity Magazine (News)
The report describes a critical, actively exploited zero-day (CVE-2026-20127) in Cisco Catalyst SD‑WAN Controller/Manager that allows unauthenticated attackers to bypass authentication, obtain high-privilege access, and manipulate NETCONF; Five Eyes agencies and CISA have issued guidance and an emergency directive to patch immediately, and investigators report attackers used a downgrade to exploit a legacy LPE (CVE-2022-20775) to escalate to root and maintain persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
