CRITICAL ALERT: Exploitation of Cisco SD-WAN appliances
ID: 30d7feac-832d-5d09-8619-81132458994c
STIX ID: report--30d7feac-832d-5d09-8619-81132458994c
Feed Name: ASD's ACSC - Alerts RSS
Date Published: 2026-03-06
Date Updated: 2026-07-24
Author: Australian Cyber Security Centre (ACSC)
Multiple national cyber agencies warn that malicious actors are actively exploiting Cisco SD-WAN vulnerabilities (notably CVE-2026-20128 and CVE-2026-20122, with prior exploitation of CVE-2026-20127 authentication bypass) to add rogue peers and gain root persistence; the alert provides a hunt guide, mitigation and hardening recommendations, and urges immediate patching and log/artefact collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
