logo

CRITICAL ALERT: Exploitation of Cisco SD-WAN appliances

ID: 30d7feac-832d-5d09-8619-81132458994c

STIX ID: report--30d7feac-832d-5d09-8619-81132458994c

Feed Name: ASD's ACSC - Alerts RSS

Threat Score
88/100

Date Published: 2026-03-06

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

Multiple national cyber agencies warn that malicious actors are actively exploiting Cisco SD-WAN vulnerabilities (notably CVE-2026-20128 and CVE-2026-20122, with prior exploitation of CVE-2026-20127 authentication bypass) to add rogue peers and gain root persistence; the alert provides a hunt guide, mitigation and hardening recommendations, and urges immediate patching and log/artefact collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.