cbcvebase.
CVE-2026-20127
published 2026-02-25

CVE-2026-20127: A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-27
Exploited in the wild
EPSS
88.24%
99.8th percentile
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Affected

346 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan_controller
ciscocatalyst_sd-wan_manager< 20.9.8.220.9.8.2
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.11 < 20.12.5.320.12.5.3
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.220.15.4.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.18.2.120.18.2.1
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager

Detection & IOCsextracted from sources · hover to see the quote

portUDP/12346
processvdaemon
path/var/log/auth.log
path/etc/passwd
path/etc/shadow
  • Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown or unauthorized IP addresses, which may indicate successful exploitation of CVE-2026-20127.
  • Hunt for suspicious peering events in logs: unauthorized peer connections at unexpected times, originating from unrecognized IP addresses, or involving device types inconsistent with the environment's architecture.
  • Look for a rogue local user account named 'troot' in /etc/passwd and /etc/shadow, created by the attacker after privilege escalation via CVE-2026-20245.
  • Monitor for malicious CSV file uploads to the SD-WAN Manager web interface, particularly files named 'evil_tenant.csv', as a post-authentication privilege escalation vector (CVE-2026-20245).
  • Monitor NETCONF access originating from the vdaemon/vmanage-admin account for unauthorized configuration changes to the SD-WAN fabric following a suspected authentication bypass.
  • UAT-8616 post-compromise actions include attempting to add SSH keys, modify NETCONF configurations, and escalate to root privileges — hunt for these specific actions on SD-WAN controllers.
  • Attacker anti-forensic behavior includes selectively deleting and restoring system configuration files and running a validation script to confirm indicators were removed — look for anomalous file deletion/restoration patterns on SD-WAN controllers.
  • The attacker changed the default admin password and then reverted it to the original value to avoid detection — monitor for rapid sequential admin password change events on SD-WAN Manager.
  • Pre-disclosure scanning activity: GreyNoise observed eight distinct surges of Cisco-targeting activity before the CVE-2026-20127 advisory, with the earliest arriving 39 days before disclosure — use session volume spikes on Cisco-related tags as an early warning signal.
  • ·CVE-2026-20127 affects the 'vdaemon' service over DTLS on UDP port 12346; systems with this port exposed to the internet are at increased risk of exploitation.
  • ·CVE-2026-20182 is a distinct vulnerability from CVE-2026-20127 in the same 'vdaemon' networking stack — it is not a patch bypass of CVE-2026-20127, so patching one does not remediate the other.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.