logo

Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access

ID: 174d0911-d0e5-5e1e-881f-526a1a904c4b

STIX ID: report--174d0911-d0e5-5e1e-881f-526a1a904c4b

Feed Name: The Hacker News

Threat Score
95/100

Date Published: 2026-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A maximum-severity authentication-bypass vulnerability (CVE-2026-20127, CVSS 10.0) in Cisco Catalyst SD-WAN Controller/Manager is being actively exploited by a sophisticated actor (UAT-8616) since 2023 to gain elevated non-root administrative access, pivot within SD-WAN management planes, downgrade software to escalate to root via CVE-2022-20775, create persistent accounts and keys, and erase forensic evidence; CISA and ASD-ACSC have issued emergency guidance and added the vulnerabilities to the Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.