⚠ Actively exploited
Added to CISA KEV on 2026-02-25. Federal agencies required to patch by 2026-02-27. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available..
CVE-2026-20127 — Improper Authentication in Cisco Catalyst Sd-wan Manager
Severity
10.0CRITICALNVD
EPSS
39.7%
top 2.68%
CISA KEV
KEV
Added 2026-02-25
Due 2026-02-27
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 25
KEV addedFeb 25
Latest updateFeb 26
KEV dueFeb 27
CISA Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Description
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an af…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0
Affected Packages3 packages
🔴Vulnerability Details
3GHSA▶
GHSA-p4cq-46q3-jr7w: A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly↗2026-02-25
💥Exploits & PoCs
1📋Vendor Advisories
2🕵️Threat Intelligence
6Threat Intel▶
UAT-8616