Cisco Zero-Day Enables Total Takeover
CriticalExecutive Summary
A critical authentication bypass zero-day vulnerability, CVE-2026-20127, is being actively exploited in Cisco Catalyst SD-WAN solutions. This flaw allows unauthenticated, remote attackers to gain administrative privileges, leading to potential full network compromise.
Vulnerability Details
- Affected Product: Cisco Catalyst SD-WAN Controller and Manager for On-Prem and Cloud-Hosted deployments in versions prior to 20.9.8.2, 20.12.5.3, 20.12.6.1, 20.15.4.2, and 20.18.2.1.
- Identifier: CVE-2026-20127
- CVSS Score: 10.0 (Critical).
- Exploitation Status: Actively Exploited.
Risk & Impact
- Triage: Immediate patching is required.
- Attack Vector: An unauthenticated, remote attacker can send crafted requests to an affected system, exploiting a flaw in the peering authentication mechanism to gain administrative access. This allows for manipulation of the SD-WAN fabric configuration, insertion of rogue devices, and unauthorized control of network traffic.
- Ease of Exploit: A sophisticated threat actor (tracked as UAT-8616) has been exploiting this vulnerability since at least 2023, indicating a readily available exploit for skilled adversaries.
Action Plan
- Immediate Action: Upgrade to a patched software version immediately.
- Workaround: No workarounds are available to address this vulnerability.
- Detection: Hunt for unauthorized control connection peering events in logs, unexpected software downgrades/upgrades, and log entries in /var/log/auth.log showing accepted public keys from unknown IP addresses.
Relevant professional terms
- Zero-Day Vulnerability
- A flaw in software or hardware that is unknown to the party responsible for patching it. When exploited by attackers, it is called a zero-day attack.
- Authentication Bypass
- A vulnerability that allows an attacker to circumvent a system's authentication measures and gain unauthorized access to protected resources or functionalities.
Source: Tenable
