VORANT. Threat Intelligence Sign in Get the full feed

CISA reports active exploitation of Cisco Catalyst SD-WAN authentication bypass…

critical vulnerability government-nationalinfrastructuretelecommunications

CISA reports active exploitation of Cisco Catalyst SD-WAN authentication bypass vulnerabilities enabling attackers to gain admin access and establish persistence.

Multiple vulnerabilities affect Cisco Catalyst SD-WAN products, with CISA reporting active exploitation of CVE-2026-20127 and CVE-2022-20775 by malicious cyber actors targeting organizations globally. The most critical flaw (CVE-2026-20127) allows unauthenticated remote attackers to bypass peering authentication mechanisms and obtain administrative privileges on SD-WAN Controller and Manager systems. Attackers have been observed chaining this zero-day with CVE-2022-20775 for privilege escalation to establish long-term persistence.

The vulnerability set includes five additional flaws affecting Cisco Catalyst SD-WAN Manager across multiple versions. CVE-2026-20129 permits unauthenticated API access with netadmin privileges, while CVE-2026-20126 allows authenticated local users to escalate to root. Additional vulnerabilities enable sensitive information disclosure (CVE-2026-20133), arbitrary file overwrites (CVE-2026-20122), and credential exposure through the Data Collection Agent feature (CVE-2026-20128). Affected versions span 20.9 through 20.18, with several EOL versions also vulnerable.

Cisco has released patches for supported versions, with some fixes scheduled for February 27, 2026. CISA's inclusion of these CVEs in the KEV catalog underscores the severity and active threat landscape. Organizations running Cisco Catalyst SD-WAN should prioritize patching, implement network segmentation, and review systems for indicators of compromise given confirmed exploitation in the wild.

Mentioned in this report

Vulnerabilities CVE-2022-20775KEVCVE-2026-20122KEVCVE-2026-20126CVE-2026-20127KEVCVE-2026-20128KEVCVE-2026-20129CVE-2026-20133KEV

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-catalyst-sd-wan-products-could-allow-for-authentication-bypass_2026-016

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free