Cisco warns of critical security flaw in SD-WAN open from 2023



  • Cisco Catalyst SD-WAN zero-day (CVE-2026-20127) exploited since 2023
  • The flaw allowed attackers to add rogue peers and manipulate network configurations
  • CISA added a bug to the KEV catalog and requested urgent patches; linked to threat group UAT-8616

“Highly sophisticated” threat actors have reportedly been exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN for more than two years, the company revealed.

Talos, Cisco’s cybersecurity arm, published a new report saying it observed a critical authentication vulnerability being actively exploited by criminals who used it to compromise controllers and add malicious and rogue peers to targeted networks.



Leave a Comment

Your email address will not be published. Required fields are marked *