CyberzSOC

Publication detail
← Back to advisories & guidance

2026-002: Multiple Vulnerabilities in Cisco Products ↗ source

February 26, 2026 CERT-EU Advisory
Co-sealed by: ASD/ACSC, CERT-EU

Summary

If exploited, these vulnerabilities could allow attackers to gain administrative access to It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023. [4] Vulnerabilities Affecting Cisco Catalyst SD-WAN Controller The vulnerability CVE-2026-20127, with the CVSS score of 10, is an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vManager. Successful exploitation allows a remote, unauthenticated attacker to obtain administrative privileges on An attacker could then modify configurations, add rogue devices to the SD-WAN fabric, extract sensitive configuration data, or establish persistent access. [1] This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

News Coverage

DateSourceArticle
2026-05-26 FortiGuard Labs Threat Signal Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-20127 10.0 Critical Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypas…
CVE-2026-20129 9.8 Critical Cisco Cisco Catalyst SD-WAN Manager A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …
CVE-2026-20126 8.8 High Cisco Cisco Catalyst SD-WAN Manager A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the unde…
CVE-2022-20775 7.8 High Cisco SD-WAN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper ac…
CVE-2026-20128 7.5 High Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain…
CVE-2026-20133 6.5 Medium Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers …
CVE-2026-20122 5.4 Medium Cisco Catalyst SD-WAN Manger Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an aff…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.