CVE-2026-20127
published 2026-02-25CVE-2026-20127: A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-27
Exploited in the wild
EPSS
88.24%
99.8th percentile
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Affected
346 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_controller | — | — |
| cisco | catalyst_sd-wan_manager | < 20.9.8.2 | 20.9.8.2 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.11 < 20.12.5.3 | 20.12.5.3 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.2 | 20.15.4.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18.2.1 | 20.18.2.1 |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown or unauthorized IP addresses, which may indicate successful exploitation of CVE-2026-20127. ↗
- →Hunt for suspicious peering events in logs: unauthorized peer connections at unexpected times, originating from unrecognized IP addresses, or involving device types inconsistent with the environment's architecture. ↗
- →Look for a rogue local user account named 'troot' in /etc/passwd and /etc/shadow, created by the attacker after privilege escalation via CVE-2026-20245. ↗
- →Monitor for malicious CSV file uploads to the SD-WAN Manager web interface, particularly files named 'evil_tenant.csv', as a post-authentication privilege escalation vector (CVE-2026-20245). ↗
- →Monitor NETCONF access originating from the vdaemon/vmanage-admin account for unauthorized configuration changes to the SD-WAN fabric following a suspected authentication bypass. ↗
- →UAT-8616 post-compromise actions include attempting to add SSH keys, modify NETCONF configurations, and escalate to root privileges — hunt for these specific actions on SD-WAN controllers. ↗
- →Attacker anti-forensic behavior includes selectively deleting and restoring system configuration files and running a validation script to confirm indicators were removed — look for anomalous file deletion/restoration patterns on SD-WAN controllers. ↗
- →The attacker changed the default admin password and then reverted it to the original value to avoid detection — monitor for rapid sequential admin password change events on SD-WAN Manager. ↗
- →Pre-disclosure scanning activity: GreyNoise observed eight distinct surges of Cisco-targeting activity before the CVE-2026-20127 advisory, with the earliest arriving 39 days before disclosure — use session volume spikes on Cisco-related tags as an early warning signal. ↗
- ·CVE-2026-20127 affects the 'vdaemon' service over DTLS on UDP port 12346; systems with this port exposed to the internet are at increased risk of exploitation. ↗
- ·CVE-2026-20182 is a distinct vulnerability from CVE-2026-20127 in the same 'vdaemon' networking stack — it is not a patch bypass of CVE-2026-20127, so patching one does not remediate the other. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
vendor_cisco·2026-02-26·CVSS 10.0
CVE-2026-20127 [CRITICAL] CWE-287 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF,
CISA
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
cisa·2026-02-25·CVSS 10.0
CVE-2026-20127 [CRITICAL] CWE-287 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Vulnerability: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Affected: Cisco Catalyst SD-WAN Controller and Manager
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged,
Cisco
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20127 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CVE-2026-20127: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non -root user account. Using this account, the attacker could a
VulDB
Cisco Catalyst SD-WAN Manager up to 20.18.2_LI_Images improper authentication (cisco-sa-sdwan-rpa-EHchtZk / Nessus ID 299998)
vuldb·2026-06-16·CVSS 10.0
CVE-2026-20127 [CRITICAL] Cisco Catalyst SD-WAN Manager up to 20.18.2_LI_Images improper authentication (cisco-sa-sdwan-rpa-EHchtZk / Nessus ID 299998)
A vulnerability was found in Cisco Catalyst SD-WAN Manager. It has been declared as critical. Affected is an unknown function. The manipulation results in improper authentication.
This vulnerability was named CVE-2026-20127. The attack may be performed from remote. In addition, an exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-p4cq-46q3-jr7w: A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly
ghsa_unreviewed·2026-02-25
CVE-2026-20127 [CRITICAL] CWE-287 GHSA-p4cq-46q3-jr7w: A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuratio
VulnCheck
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
vulncheck·2026·CVSS 10.0
CVE-2026-20127 [CRITICAL] CWE-287 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access
No detection rules found.
Hackernews
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
blogs_hackernews·2026-06-25·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.
The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges by supplying a crafted file to the affected system by taking advantage of the device's insufficient validation of user-supplied input.
Earlier this month, Cisc
Bleepingcomputer
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
blogs_bleepingcomputer·2026-06-24·CVSS 10.0
CVE-2026-20245 [CRITICAL] Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
## Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
## Lawrence Abrams
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices.
The CVE-2026-20245 vulnerability is a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) that allows authenticated attackers to execute arbitrary commands as root by uploading a crafted file.
Cisco said the vulnerability stemmed from insufficient validation of user-supplied input and could be exploited by authenticated attackers with local access to affected devices.
When Cisco disclosed the flaw earlier this month, the company warned
Hackernews
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
blogs_hackernews·2026-06-18
CVE-2026-20127 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
The internet did not break this week. It got used exactly as designed, which is worse.
Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells.
Add exposed edge gear, poisoned packages, cash courier scams, stealers, loaders, and phishing that barely bothers pretending anymore. Here’s the full mess.
Microsoft has announced that DNS-over-HTTP
Hackernews
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
blogs_hackernews·2026-06-16·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-20262 , carries a CVSS score of 6.5 out of 10.0.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in an advisory.
The issue, the networking equipment company added, stems from inadequat
Hackernews
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
blogs_hackernews·2026-06-06·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245 , carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary co
Bleepingcomputer
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
blogs_bleepingcomputer·2026-06-05·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Sergiu Gatlan
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245 ) actively exploited in attacks enabling root privilege escalation.
The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root.
"An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the atta
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Hackernews
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
blogs_hackernews·2026-05-15·CVSS 5.4
CVE-2026-20182 [MEDIUM] CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026.
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182 . It's rated 10.0 on the CVSS scoring system, indicating maximum severity.
"Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass vulnerability
Rapid7
The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
blogs_rapid7·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
Imagine you build a massive corporate campus with every security control money can buy. Blast resistant doors. Biometric scanners. Guards at every entrance. Maybe something similar to the infamous Death Star. On paper, it looks fantastic. Then, somewhere along the way, somebody decides the maintenance team needs a universal key that opens every door in the building without setting off any alarms.
That certainly makes operations easier, but it also means one mistake, one compromise (like a well placed photon torpedo), or one very bad decision can unravel the whole thing.
That is basically the problem we keep running into in modern enterprise networking.
## Why SD-WAN controllers create concentrated risk
This week, Rapid7 researchers Stephen Fewer and Jonah Burgess disclosed CVE-2026-201
Hackernews
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
blogs_hackernews·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.
The vulnerability, tracked as CVE-2026-20182 , carries a CVSS score of 10.0.
"A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system," C
Tenable
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
blogs_tenable·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2
Bleepingcomputer
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
blogs_bleepingcomputer·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
## Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
## Lawrence Abrams
Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices.
CVE-2026-20182 has a maximum severity of 10.0 and impacts Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager in on-prem and SD-WAN Cloud deployments.
In an advisory published today, Cisco said the issue stems from a peering authentication mechanism that "is not working properly."
"This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by
Talos
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
blogs_talos·2026-05-14·CVSS 5.4
CVE-2026-20182 [MEDIUM] Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
## Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Cisco Talos is tracking the active exploitation of CVE-2026-20182 , an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.
Successful exploitation of CVE-2026-20182 allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
The exploitation of CVE-2026-20182 appears to have been limited so far and Talos clusters this activity under UAT-8616 with high confidence.
Talos is also aware of a series of threat actors, distinct from UAT-8616, that have been observed to be exploiting a different, previously disclosed set of vulnerabilities, in a new way than p
Rapid7
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
blogs_rapid7·2026-05-14·CVSS 10.0
CVE-2026-20127 [CRITICAL] CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
## Overview
While researching a critical authentication bypass vulnerability, CVE-2026-20127 , which was exploited in-the-wild , Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182 .
This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346), which is the same service that was vulnerable to CVE-2026-20127. The new vulnerability is not a patch bypass of CVE-2026-20127. It is a different issue located in a similar part of the “vdaemon” networking stack.
This impact however is the same, a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations , such as inj
Rapid7
Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
blogs_rapid7·2026-05-06·CVSS 9.3
CVE-2026-0300 [CRITICAL] Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
## Overview
On May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300 , a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliances. Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. The vulnerability carries a CVSSv4 score of 9.3 and has been confirmed as exploited in the wild by the vendor.
CVE-2026-0300 is a buffer overflow ( CWE-787 ) in the User-ID™ Authentication Portal (also known as Captive Portal), a non-default PAN-OS feature used to map IP addresses to usernames. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted packets to a device with the Authentication Portal enabled, achieving arbitrary code execution with
Bleepingcomputer
CISA flags new SD-WAN flaw as actively exploited in attacks
blogs_bleepingcomputer·2026-04-21·CVSS 5.4
CVE-2026-20133 [MEDIUM] CISA flags new SD-WAN flaw as actively exploited in attacks
## CISA flags new SD-WAN flaw as actively exploited in attacks
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks.
Catalyst SD-WAN Manager (formerly known as vManage) is a network management software that helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
Cisco patched this information disclosure vulnerability ( CVE-2026-20133 ) in late February, saying that it allows unauthenticated remote attackers to access sensitive information on unpatched devices.
"This vulnerability is due to insufficient file system access restrictions. An attacker could exploit
Greynoiseio
The Internet Changes Before the Advisory Drops
blogs_greynoiseio·2026-04-20·CVSS 4.9
CVE-2026-20127 [MEDIUM] The Internet Changes Before the Advisory Drops
Before Cisco published its advisory for CVE-2026-20127 — a CVSS 10.0 zero-day cited in a Five Eyes joint warning — GreyNoise sensors had already observed eight distinct surges of Cisco-targeting activity. The earliest arrived 39 days before disclosure. Each one came closer than the last. A new study finds this pattern is not an anomaly.
What the Data Shows
Over 103 days, GreyNoise tracked 147.8 million sessions across 276 vendor-specific tags covering 18 network infrastructure vendors. Of 104 detected surge events, 68 preceded a vendor-matched CVE — spanning 33 vulnerabilities across 16 vendor families. Statistical testing confirmed the pattern is not coincidence.
Median lead time: 11 days. 49% of surges arrived within 10 days of disclosure. 78% within 21 days.
Session volume is the
Rapid7
CVE-2026-33032: Nginx UI Missing MCP Authentication
blogs_rapid7·2026-04-16·CVSS 9.8
CVE-2026-33032 [CRITICAL] CVE-2026-33032: Nginx UI Missing MCP Authentication
## Overview
On March 30, 2026, a security advisory was published for a critical vulnerability affecting Nginx UI . Nginx UI is an open-source web interface to centralize the management of Nginx configurations and SSL certificates. The critical vulnerability, CVE-2026-33032 , was reported in early March by Pluto Security researcher Yotam Perkal and subsequently patched on March 15, 2026. That same day, Pluto Security published a technical blog post with some vulnerability details.
CVE-2026-33032 is a missing authentication bug with a CVSS score of 9.8 ; as a result of missing authentication controls, an unauthenticated attacker can access a Model Context Protocol (MCP) server that can perform privileged operations on managed Nginx web servers. Systems are vulnerable in the default IP allo
Rapid7
Metasploit Wrap-Up 04/10/2026
blogs_rapid7·2026-04-10·CVSS 10.0
[CRITICAL] Metasploit Wrap-Up 04/10/2026
## Speedup Improvements of MSFVenom & New Modules
This week, we have added new modules to Metasploit Framework targeting Cisco Catalyst SD-WAN controllers and osTicket as well as updates and improvements to Windows service-for-user persistence, and LDAP/ADCS-related modules to automatically report related services resulting in an improved data stream, which can be queried by using the services command.
We also landed an improvement to msfvenom’s bootup time, thanks to bcoles , resulting in an approximate two-times speedup.
## New module content (4)
## AD/CS Authenticated Web Enrollment Services Module
Authors: Spencer McIntyre, bwatters-r7, and jhicks-r7
Type: Auxiliary
Pull request: #20752 contributed by bwatters-r7
Path: admin/http/web_enrollment_cert
Description: This adds a ne
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·2026-03-12·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
## February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026 . All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
APT28 exploits MSHTML fl
Bleepingcomputer
Cisco flags more SD-WAN flaws as actively exploited in attacks
blogs_bleepingcomputer·2026-03-05·CVSS 5.4
[MEDIUM] Cisco flags more SD-WAN flaws as actively exploited in attacks
## Cisco flags more SD-WAN flaws as actively exploited in attacks
## Sergiu Gatlan
Cisco has flagged two Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices.
Catalyst SD-WAN Manager (formerly vManage) is network management software that enables admins to monitor and manage up to 6,000 Catalyst SD-WAN devices from a single centralized dashboard.
"In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only," the company warned in an update to a February 25 advisory.
"The vulnerabilities that are described in the other CVEs in this advisory are not known to have been compromised. Cisco strongly recommends that customers upgr
Checkpoint
2nd March – Threat Intelligence Report
blogs_checkpoint·2026-03-02
CVE-2025-59536 2nd March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate the stolen dataset includes HR-related information, including contact details and employment records f
Talos
Henry IV, Hotspur, Hal, and hallucinations
blogs_talos·2026-02-26
Henry IV, Hotspur, Hal, and hallucinations
Welcome to this week’s edition of the Threat Source newsletter.
> "'Tis dangerous to take a cold, to sleep, to drink; but I tell you, my lord fool, out of this nettle, danger, we pluck this flower, safety." - Hotspur, Shakespeare’s Henry IV, Part 1: Act 2 Scene 3
I get it. Hotspur is the quintessential hothead, and we all understand his place in the story. He’s famous for his fiery temperament and impatience with anything that smells of caution or compromise. Hotspur’s whole deal is that you have to take risks if you want to achieve anything worthwhile, but he’s not wrong... at least not fully. Anyone who has been in this field for a while has seen risks lead to disaster and risks lead to success. There is no silver bullet and there is no black and white.
Wait, am I talking about Henry
Talos
Henry IV, Hotspur, Hal, and hallucinations
blogs_talos·2026-02-26
Henry IV, Hotspur, Hal, and hallucinations
## Henry IV, Hotspur, Hal, and hallucinations
Welcome to this week’s edition of the Threat Source newsletter.
"'Tis dangerous to take a cold, to sleep, to drink; but I tell you, my lord fool, out of this nettle, danger, we pluck this flower, safety." - Hotspur, Shakespeare’s Henry IV, Part 1: Act 2 Scene 3
I get it. Hotspur is the quintessential hothead, and we all understand his place in the story. He’s famous for his fiery temperament and impatience with anything that smells of caution or compromise. Hotspur’s whole deal is that you have to take risks if you want to achieve anything worthwhile, but he’s not wrong... at least not fully. Anyone who has been in this field for a while has seen risks lead to disaster and risks lead to success. There is no silver bullet and there is no blac
Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
blogs_talos·2026-02-25·CVSS 7.8
CVE-2026-20127 [HIGH] Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
Cisco Talos is tracking the active exploitation of CVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on the affected system by sending a crafted request to an affected system. Successful exploitation may allow the attacker to gain administrative privileges on the Controller as an internal, high privileged, non-root, user account.
Talos clusters this exploitation and subsequent post-compromise activity as “UAT-8616” whom we assess with high confidence is a highly sophisticated cyber threat actor. After the discovery of active exploitation of the 0-day in the wild, we were able to find evidence that the malicious activity went back at least three y
Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
blogs_talos·2026-02-25·CVSS 7.8
CVE-2026-20127 [HIGH] Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
## Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
Cisco Talos is tracking the active exploitation of CVE-2026-20127 , a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on the affected system by sending a crafted request to an affected system. Successful exploitation may allow the attacker to gain administrative privileges on the Controller as an internal, high privileged, non-root, user account.
Talos clusters this exploitation and subsequent post-compromise activity as “UAT-8616” whom we assess with high confidence is a highly sophisticated cyber threat actor. After the discovery of active exploitation of the 0-day in the wild, we were able to find e
Bleepingcomputer
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
blogs_bleepingcomputer·2026-02-25·CVSS 10.0
CVE-2026-20127 [CRITICAL] Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
## Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
## Lawrence Abrams
Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks.
CVE-2026-20127 has a maximum severity of 10.0 and impacts Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) in on-prem and SD-WAN Cloud installations.
Cisco credited the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) for reporting the vulnerability.
In an advisory published today, Cisco said the issue stems from a peering authentication mechanis
Tenable
CVE-2026-20127 Zero-Day Auth Bypass Exploited
blogs_tenable·2026-02-25·CVSS 5.4
CVE-2026-20128 [MEDIUM] CVE-2026-20127 Zero-Day Auth Bypass Exploited
March 5: This blog has been updated to include a reference to CVE-2026-20128 and CVE-2026-20122, two additional SD-WAN Manager vulnerabilities that Cisco has confirmed have been exploited in the wild.
Threat Intel
UAT-8616
threat_intel·CVSS 7.8
CVE-2026-20127 [HIGH] UAT-8616
# Threat Actor: UAT-8616
## Description
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
Wiz
CVE-2026-20128 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20128 [CRITICAL] CVE-2026-20128 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20128 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system.
This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Source : NVD
## 7.5
Score
Published Febr
Wiz
CVE-2026-20129 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20129 [MEDIUM] CVE-2026-20129 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20129 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Source : NVD
## 9.8
Score
Published February 25, 2026
Severity CRITICAL
CNA Score 9.8
Affe
Wiz
CVE-2026-20133 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20133 [MEDIUM] CVE-2026-20133 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20133 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
Cisco SD-WAN Catalyst Manager
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EP
Wiz
CVE-2026-20108 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20108 [MEDIUM] CVE-2026-20108 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20108 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologi
Wiz
CVE-2026-20126 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20126 [MEDIUM] CVE-2026-20126 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20126 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system.
This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.
Source : NVD
## 7.8
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Cisco SD-WAN Catalyst Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Du
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
# February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026. All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
- Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
- Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
- APT28 exploits MSHTML
Wiz
CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20122 [MEDIUM] CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20122 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Source : NVD
## 5.4
Score
Published February 25, 2026
Severity MEDIUM
CNA Score 5.4
Affe
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Wiz
CVE-2026-20127 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20127 [CRITICAL] CVE-2026-20127 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20127 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker co
2026-02-25
Published
2026-02-25
Added to CISA KEV
Exploited in the wild