logo

CVE-2026-20127: Cisco Catalyst SD-WAN Auth Bypass Exploited In The Wild

ID: 4e8ba37b-7e73-59fc-8155-8da95f0b04d8

STIX ID: report--4e8ba37b-7e73-59fc-8155-8da95f0b04d8

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**CVE-2026-20127:** A critical (CVSS 10.0) authentication-bypass vulnerability in Cisco Catalyst SD-WAN controller and manager components is being actively exploited in the wild, allowing unauthenticated attackers to gain high-privilege internal access; Cisco and federal agencies have issued urgent patching guidance and mitigations to remove internet exposure and hunt for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.