CyberzSOC

Publication detail
← Back to advisories & guidance

CSA: Exploitation of SD-WAN Appliances ↗ source

February 25, 2026 NSA Advisory
Co-sealed by: ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NSA

Summary

Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs. The following agencies, hereafter referred to as the authoring organizations, released a Cisco SD-WAN Threat Hunt Guide, based on investigative data, to support network defenders’ detection of and response to the malicious actors’ threat activity. The Hunt Guide is being released by the following authoring and co-sealing agencies: The authoring organizations strongly urge network defenders to: Catalyst SD-WAN Controller Authentication Bypass Vulnerability, and fully patch SD-WAN technology, including for CVE-2026-20127; Cisco’s Catalyst SD-WAN hardening guidance should be reviewed in full and includes isolate VPN 512 interfaces, and use IP blocks for manually provisioned edge IPs. PP-26-0656 | February 2026 Ver. 1.0 Cyber Centre, NCSC-NZ, and NCSC-UK Notices and contact information The information and opinions contained in this document are provided "as is" and without any warranties or guarantees.

News Coverage

DateSourceArticle
2026-05-26 FortiGuard Labs Threat Signal Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-20127 10.0 Critical Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypas…
CVE-2026-20126 8.8 High Cisco Cisco Catalyst SD-WAN Manager A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the unde…
CVE-2026-20128 7.5 High Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain…
CVE-2026-20122 5.4 Medium Cisco Catalyst SD-WAN Manger Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an aff…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.