Malware & Threats Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers Already added to CISAâs KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges. By Ionut Arghire | February 26, 2026 (4:18 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Cisco on Wednesday rolled out emergency patches for a critical Catalyst SD-WAN zero-day vulnerability that has been exploited in the wild. Tracked as CVE-2026-20127 (CVSS score of 10/10), the flaw can be exploited remotely to bypass authentication and obtain administrative privileges on a vulnerable device. The issue affects the peering authentication mechanism of Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Catalyst SD-WAN Manager (formerly SD-WAN vManage), allowing unauthenticated, remote attackers to send crafted requests. Successful exploitation results in the attacker logging in as âan internal, high-privileged, non-root user accountâ, Cisco explains in its advisory . âUsing this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric,â the company notes. The security defect was addressed with the release of Cisco Catalyst SD-WAN versions 20.12.6.1, 20.12.5.3, 20.12.6.1, 20.15.4.2, and 20.18.2.1. Patches will also be included in version 20.9.8.2, expected to be released on Friday. Advertisement. Scroll to continue reading. Cisco says it is aware of the limited exploitation of the vulnerability and has released indicators of compromise (IoCs) to help organizations hunt for malicious activity targeting internet-exposed Catalyst SD-WAN systems. On Wednesday, the US cybersecurity agency CISA added the zero-day and an older Cisco Catalyst SD-WAN bug, CVE-2022-20775, to its Known Exploited Vulnerabilities (KEV) catalog and issued Emergency Directive 26-03, urging federal agencies to patch both within two days. CVE-2022-20775, disclosed in September 2022, is a high-severity path traversal issue that allows an authenticated attacker to execute arbitrary commands with root privileges. CISA and peer agencies in Five Eyes countries say that threat actors have chained the two flaws to bypass authentication, escalate privileges, and establish persistence on Catalyst SD-WAN systems. The attacks were attributed by Cisco Talos to UAT-8616 , a âhighly sophisticated cyber threat actorâ that has been active since at least 2023. After adding an administrative account to vulnerable systems, the adversary downgraded the software to a version vulnerable to CVE-2022-20775 and achieved persistence as root, the Five Eyes agencies explain ( PDF ). Talos has not linked the attack to a known threat group or a specific country, but it recently warned about a China-nexus group identified as UAT-9686 exploiting a Cisco product zero-day tracked as CVE-2025-20393. ED 26-03 mandates that all in-scope agencies immediately inventory Catalyst SD-WAN systems and ensure they store logs externally, collect specific artefacts, and update them to patched software releases. On Wednesday, Cisco also announced fixes for five Catalyst SD-WAN Manager flaws, including a critical-severity authentication bypass impacting the API user authentication mechanism, and for nine high- and medium-severity bugs in other products, but said it was not aware of any of them being exploited in the wild. Related: Cisco, F5 Patch High-Severity Vulnerabilities Related: Hackers Targeting Cisco Unified CM Zero-Day Related: Cisco Patches Vulnerability Exploited by Chinese Hackers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. More from Ionut Arghire Astelia Raises $35 Million for Exposure Management Ad Tech Company Optimizely Targeted in Cyberattack âArkanix Stealerâ Malware Disappears Shortly After Debut New âSandworm_Modeâ Supply Chain Attack Hits NPM GitHub Issues Abused in Copilot Attack Leading to Repository Takeover Anonymous FĂ©nix Members Arrested in Spain Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud Romanian Hacker Pleads Guilty to Selling Access to US State Network Latest News The Blast Radius Problem: Stolen Credentials Are Weaponizing Agentic AI Google Disrupts Chinese Hackers Targeting Telecoms, Governments SolarWinds Patches Four Critical Serv-U Vulnerabilities Medical Device Maker UFP Technologies Hit by Cyberattack Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia CarGurus Data Breach Impacts Over 12 Million Users SecurityWeek Report: 426 Cybersecurity M&A Deals Announced in 2025 Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeekâs 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize todayâs ransomware extortion threats. Submit People on the Move Menlo Security has named Bill Robbins as Chief Executive Officer. Axonius has named a new CMO and a new AFS leader. Wealth management platform Envestnet announced the appointment of Rich Friedberg as CISO. More People On The Move Expert Insights How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures donât always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isnât a hypothetical but a natural continuation of the tradecraft weâve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Canât Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email
A critical authentication bypass vulnerability (CVE-2026-20127, CVSS 10.0) in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain high-privileged administrative access by sending crafted requests, enabling them to manipulate the SD-WAN fabric via NETCONF. This flaw has been actively exploited in the wild by a sophisticated threat actor, UAT-8616, who has chained it with an older path traversal flaw (CVE-2022-20775, CVSS 7.8) for privilege escalation and persistence. Cisco has released patches in versions 20.12.6.1, 20.12.5.3, 20.15.4.2, and 20.18.2.1, and CISA has mandated urgent remediation by adding both CVEs to its Known Exploited Vulnerabilities catalog.