CVE-2026-20127

Published Feb 25, 2026

Last updated a month ago

Exploit knownCVSS critical 10.0
Network
Zero-day
API
ICS
Tunneling protocol
Bgp
Firmware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20127 is an authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw resides within the peering authentication mechanism, which is responsible for establishing trust relationships between SD-WAN components. An unauthenticated, remote attacker can exploit this vulnerability by sending specially crafted requests to an affected system, thereby bypassing the authentication process. Successful exploitation allows the attacker to gain administrative privileges on the affected system, enabling them to log in as a high-privileged, non-root user. From there, the attacker can access NETCONF, which permits the manipulation of network configurations for the entire SD-WAN fabric. This vulnerability has been actively exploited in the wild by sophisticated threat actors, with evidence of malicious activity dating back to 2023.

Description
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 
Source
psirt@cisco.com
NVD status
Modified
Products
catalyst_sd-wan_manager, sd-wan_vsmart_controller

Risk scores

CVSS 3.1

Type
Primary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Exploit added on
Feb 25, 2026
Exploit action due
Feb 27, 2026
Required action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weaknesses

psirt@cisco.com
CWE-287
nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending
  1. Cisco SD-WANのゼロデイ脆弱性CVE-2026-20245は、公式開示の2か月前には悪用され、通信サービス事業者でのrootアクセス取得に使用されていた。Google報告。攻撃の第一波はCVE-2026-20127とCVE-2026-20182を使用し、その後CVE-2

    @__kokumoto

    24 Jun 2026

    841 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-20133: CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager formerly vManage < 20.18 CISA KEV: Yes — federal deadline passed April 24 CVE-2026-20133, May 8 CVE-2026-20128 Exploitation Status: Actively…

    @lyrie_ai

    14 Jun 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Cisco ha confermato lo sfruttamento attivo di CVE-2026-20245 nel Catalyst SD-WAN Manager — il settimo zero-day sulla piattaforma dall'inizio del 2026. L'attore UAT-8616, attivo su questi sistemi dal 2023, ha già sfruttato CVE-2026-20127 e CVE-2026-20182 (CVSS 10.0 auth bypass)

    @trinacriatech

    9 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CVE-2026-20182: Today @rapid7 and Cisco are disclosing CVE-2026-20182, a critical (CVSS 10.0) auth bypass affecting Cisco Catalyst SD-WAN Controller, found by @CryptoCat and I when we were researching CVE-2026-20127 last Feb. An unauth attacker can become the vmanage-admin…

    @lyrie_ai

    18 May 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CISA just revealed a critical Cisco SD-WAN flaw (CVE-2026-20127) was actively exploited since 2023, granting attackers admin access for years. Patching isn't enough; deep compromise requires a full rebuild. https://t.co/GwvqZUwQCb #cybersecurity #cisa #cisco https://t.co/aC3MF1

    @thepixelspulse

    21 Apr 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 BREAKING: CISA orders federal agencies to patch actively exploited Cisco SD-WAN flaws granting attackers admin access to government networks. CVE-2026-20127 has been exploited since 2023. #BreakingNews #Cybersecurity #USA #CiscoSDWAN https://t.co/FJ4qFG0Mpt

    @Archange_Shadow

    21 Apr 2026

    58 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. MAR 2026-A critical vulnerability impacting Cisco Catalyst SD-WAN systems has been identified across the DIB. CVE-2026-20127 is an authentication bypass exploited by nation-state actors since 2023. Per CISA ED 26-03 & NSA advisory, patch & hunt now. #KnowledgeByte #DIB ht

    @DC3VDP

    13 Apr 2026

    121 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. [TECH] **Five Eyes Issue Emergency Directive Over Cisco SD-WAN Zero-Day Exploited Since 2023** CISA and its Five Eyes partners — the UK, Australia, Canada, and New Zealand — issued a coordinated emergency directive Tuesday over CVE-2026-20127, a CVSS 10.0 authentication byp

    @DarkForgeNews

    1 Apr 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access https://t.co/cAGkijADhk #Cisco #SDWAN #CyberSecurity #ZeroDay #CVE2026 https://t.co/YYeB7irMXU

    @blueteamsec1

    27 Mar 2026

    574 Impressions

    2 Retweets

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 CVE-2026-20127 (CVSS 10.0): Cisco Catalyst SD-WAN auth bypass → root access, exploited since 2023 (UAT-8616). CISA ED 26-03! https://t.co/hf7QcrCLrM

    @TheRabbitPy

    23 Mar 2026

    53 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Three major Cisco management platform vulnerabilities in 2026. All in web interfaces. All CVSS 9+. CVE-2026-20131 (FMC) — CVSS 10, RCE as root CVE-2026-20127 (SD-WAN vManage) — RCE CVE-2023-20198 (IOS-XE web UI) — privilege escalation The pattern is undeniable: web-based

    @FirstPassLab

    21 Mar 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA warns that patched flaws in Ivanti EPM and Cisco SD-WAN are being actively exploited. Ivanti (CVE-2026-1603): Credential leaks. Cisco (CVE-2026-20127): Auth bypass (exploited since 2023) If you run these, check your patch levels and logs immediately. https://t.co/XFLnC17pPG

    @GetTCT

    16 Mar 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Top 5 Trending CVEs: 1 - CVE-2026-20127 2 - CVE-2023-43010 3 - CVE-2026-21385 4 - CVE-2025-68613 5 - CVE-2026-25185 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    13 Mar 2026

    243 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. ‼️ CVE-2026-20127: Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access. PoC: https://t.co/fbEaySQRfP "This repository contains a working proof-of-concept exploit for CVE-2026-20127, a critical pre-authentication vulnerability in Cisco Catalyst SD-WAN

    @DarkWebInformer

    9 Mar 2026

    6077 Impressions

    9 Retweets

    37 Likes

    19 Bookmarks

    1 Reply

    0 Quotes

  15. PoC is now public for CVE-2026-20127 in Cisco Catalyst SD-WAN. UAT-8616 has been exploiting it since 2023, now anyone can try. Two more SD-WAN flaws also active: CVE-2026-20122 and CVE-2026-20128. Patch window is effectively closed. https://t.co/gZOpZQntR2

    @CybrPulse

    7 Mar 2026

    80 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 3 Cisco SD-WAN CVEs actively exploited in 8 days. Here's the scorecard: CVE-2026-20127 — CVSS 10.0 — Auth bypass zero-day — Exploited since 2023 CVE-2026-20128 — CVSS 5.5 — DCA credential leak — Exploited (confirmed March 5) CVE-2026-20122 — CVSS 7.1 — File overw

    @FirstPassLab

    5 Mar 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-20127 3 - CVE-2025-59536 4 - CVE-2026-27509 5 - CVE-2026-27739 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Feb 2026

    246 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. #AppSec #Threat_Research 1⃣ Abusing Cortex XDR Live https://t.co/iDFLbQUjDQ 2⃣ Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20127) https://t.co/BCwOGH8XHu 3⃣ OpenSSL Vulnerability (CVE-2025-15467) https://t.co/0CF1aieVHL

    @ksg93rd

    26 Feb 2026

    425 Impressions

    3 Retweets

    9 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

Configurations