HomeUpdatesCisco fixes zero-day vulnerability in Catalyst SD-WAN

Cisco fixes zero-day vulnerability in Catalyst SD-WAN

Cisco has released emergency patches for a critical zero-day vulnerability in Catalyst SD-WAN that the company says has already been exploited in real-world attacks. The vulnerability, tracked as CVE -2026-20127 with a maximum CVSS score of 10/10 , allows remote attackers to bypass authentication and gain privileged access to vulnerable devices.

Cisco Catalyst SD-WAN

The seriousness of the case is not limited to theoretical risk. On the contrary, it is a vulnerability that has already been the subject of limited but confirmed exploitation, which has mobilized both Cisco and US cybersecurity authorities.

What is CVE-2026-20127 and how does the attack work?

The issue is located in the peering authentication mechanism of the Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage). Through properly crafted requests, an unauthorized attacker can gain access as an “internal user with elevated privileges.”

See also: Zyxel: Critical RCE vulnerability affects many routers

Although this account does not have root privileges by default, it opens the way to access the NETCONF interface, which is used to manage and configure network devices. Through this access, the attacker can modify the configuration of the SD-WAN fabric, affecting data traffic, routing policy, and potentially the availability of critical services.

Simply put, successful exploitation allows complete control of an organization's SD-WAN architecture, with implications ranging from espionage to network sabotage.

Cisco: Immediate fixes and updates available

Cisco has released patches for multiple versions of Catalyst SD-WAN, including 20.12.6.1, 20.12.5.3, 20.15.4.2, and 20.18.2.1, with fixes coming in the upcoming 20.9.8.2. Cisco has also released indicators of compromise (IoCs) so organizations can identify suspicious activity, especially on systems exposed to the internet.

The issue gained even more traction when the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20127 to its list of Known Exploited Vulnerabilities (KEV) . Along with it, the older CVE-2022-20775 , a path traversal flaw that allows an authorized user to execute arbitrary commands with root privileges , was added .

See also: CISA: FileZen vulnerability in KEV Catalog

Cisco fixes zero-day vulnerability in Catalyst SD-WAN

CISA gave federal agencies just two days to implement fixes, underscoring the level of risk.

Chain of custody and persistence

According to an analysis by Cisco Talos, the attacks are attributed to the UAT-8616, a highly sophisticated threat actor that has been active since at least 2023. The attackers allegedly combined the two CVEs in a chain attack: first bypassing authentication via the zero-day, adding an administrator account , and then downgrading the software to a version vulnerable to CVE-2022-20775.

In this way, they achieve privilege escalation to root and install persistence mechanisms, ensuring long-term access to the system. Cybersecurity services of the Five Eyes have confirmed that this technique allows full control and persistence on the target network.

Although Talos has not officially attributed the campaign to a specific country, recent reports from the company point to another group with links to China, known as UAT-9686, which has also targeted Cisco products.

Business implications and compliance requirements

CISA Directive 26-03 goes beyond simply installing patches. It requires agencies to promptly document all Catalyst SD-WAN systems, ensure off-site log storage, collect specific artifacts, and verify that they are running patched versions.

See also: SolarWinds Serv-U: Critical vulnerabilities allow root access

For businesses, the incident serves as a reminder that SD-WAN infrastructures are now a critical pillar of connectivity, especially in multi-cloud and hybrid work environments. A controller-level breach can impact dozens or even hundreds of branch offices.

Cisco fixes zero-day vulnerability in Catalyst SD-WAN

Additional vulnerabilities and the broader context

On the same day, Cisco announced fixes for five more vulnerabilities in Catalyst SD-WAN Manager, including a critical authentication bypass in the API mechanism. It also fixed nine high- and medium-severity bugs in other products. While there is no evidence of active exploitation for these, the timing highlights the increasing pressure on networking equipment vendors.

In an era where attacks are multi-stage and strategically planned, speed of response and transparency in customer notification are critical indicators of trustworthiness. This zero-day is a reminder that even mature platforms can become entry points when a critical authentication mechanism fails.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS