CVE-2026-20127

critical

Description

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

From the Tenable Blog

CVE-2026-20127 Zero-Day Auth Bypass Exploited
CVE-2026-20127 Zero-Day Auth Bypass Exploited

Published: 2026-02-25

CVE-2026-20127 Zero-Day Auth Bypass Exploited

References

https://hackread.com/us-agencies-cisa-deadline-critical-cisco-sd-wan-flaw/

https://www.infosecurity-magazine.com/news/cisa-cisco-sd-wan-flaws-directive/

https://www.databreachtoday.com/hacker-free-for-all-over-cisco-sd-wan-flaw-a-30946

https://www.securityweek.com/recent-cisco-catalyst-sd-wan-vulnerability-now-widely-exploited/

https://www.theregister.com/2026/03/06/cisco_sdwan_bugs/

https://securityaffairs.com/189056/security/cisco-flags-ongoing-exploitation-of-two-recently-patched-catalyst-sd-wan-flaws.html

https://www.securityweek.com/cisco-warns-of-more-catalyst-sd-wan-flaws-exploited-in-the-wild/

https://www.helpnetsecurity.com/2026/03/05/cisco-cve-2026-20128-cve-2026-20122-exploited/

https://www.darkreading.com/vulnerabilities-threats/cisco-48-firewall-vulnerabilities-2-critical

https://www.bleepingcomputer.com/news/security/cisco-flags-more-sd-wan-flaws-as-actively-exploited-in-attacks/

https://thehackernews.com/2026/03/cisco-confirms-active-exploitation-of.html

https://www.theregister.com/2026/02/26/five_eyes_cisco_sdwan/

https://www.sophos.com/en-us/blog/cisco-sd-wan-vulnerabilities-cve-2026-20127-cve-2022-20775-in-active-exploitation

https://www.securityweek.com/cisco-patches-catalyst-sd-wan-zero-day-exploited-by-highly-sophisticated-hackers/

https://www.infosecurity-magazine.com/news/immediate-patch-cisco-catalyst/

https://www.darkreading.com/vulnerabilities-threats/cisco-sd-wan-zero-day-exploitation-3-years

https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html

https://securityaffairs.com/188548/hacking/u-s-cisa-adds-cisco-sd-wan-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://securityaffairs.com/188540/security/hackers-abused-cisco-sd-wan-zero-day-since-2023-to-gain-full-admin-control.html

https://www.helpnetsecurity.com/2026/02/25/cisco-sd-wan-zero-day-cve-2026-20127/

https://www.databreachtoday.com/feds-scramble-amid-shutdown-to-secure-cisco-sd-wan-systems-a-30849

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/exploitation-of-cisco-sd-wan-appliances

https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems

https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-and-partners-release-guidance-ongoing-global-exploitation-cisco-sd-wan-systems

https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-adds-two-known-exploited-vulnerabilities-catalog

https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/

https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk

https://cyberscoop.com/cisco-zero-days-cisa-emergency-directive-five-eyes/

https://blog.talosintelligence.com/uat-8616-sd-wan/

Details

Source: Mitre, NVD

Published: 2026-02-25

Updated: 2026-02-26

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.03264

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest