CVE-2026-20127Active Exploitation(cisco / catalyst_sd-wan_manager)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 116 mentions and remains active

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-27. Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager
  • sd-wan_vbond_orchestrator
  • sd-wan_vsmart_controller

Threat summary

  • Active exploitation appears in 299 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 416 mentions across 56 observed days

What's happening

  • Active exploitation reported across 299 signals
  • Exploit tool or code specified in 22 signals
  • PoC mentioned or linked in 32 signals
  • Patch or workaround mentioned in 138 signals
  • Technical details provided in 245 signals
  • General: 47 classified signals
  • Disclosure: 35 classified signals
  • Peaked 54d ago at 116 mentions (2026-02-26); latest day: 1
  • 416 total mentions across 56 days

Affected systems

Vendors
Products
catalyst_sd-wan_managersd-wan_vbond_orchestratorsd-wan_vsmart_controller

1 version affected across 3 products

Deep dive

Activity timeline416 mentions / 56d
0295887116Mentions · 2026-02-25: 49Mentions · 2026-02-26: 116Mentions · 2026-02-27: 38Mentions · 2026-02-28: 15Mentions · 2026-03-01: 9Mentions · 2026-03-02: 25Mentions · 2026-03-03: 10Mentions · 2026-03-04: 12Mentions · 2026-03-05: 16Mentions · 2026-03-06: 17Mentions · 2026-03-07: 6Mentions · 2026-03-08: 6Mentions · 2026-03-09: 9Mentions · 2026-03-10: 7Mentions · 2026-03-11: 5Mentions · 2026-03-12: 8Mentions · 2026-03-13: 7Mentions · 2026-03-14: 5Mentions · 2026-03-16: 3Mentions · 2026-03-17: 1Mentions · 2026-03-18: 2Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-03-27: 1Mentions · 2026-04-01: 1Mentions · 2026-04-03: 2Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 2Mentions · 2026-04-17: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-05-01: 1Mentions · 2026-05-05: 2Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 5Mentions · 2026-05-16: 1Mentions · 2026-05-18: 3Mentions · 2026-05-24: 1Mentions · 2026-06-01: 1Mentions · 2026-06-05: 2Mentions · 2026-06-06: 1Mentions · 2026-06-07: 1Mentions · 2026-06-09: 3Mentions · 2026-06-14: 2Mentions · 2026-06-17: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Mentions · 2026-07-18: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-02-26: 5PoC Mentioned / Linked · 2026-02-28: 2PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-04: 4PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-06: 4PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-03-09: 2PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-11: 2PoC Mentioned / Linked · 2026-03-12: 3PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-06-27: 1Exploit Tool / Code · 2026-02-26: 2Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-02-28: 1Exploit Tool / Code · 2026-03-02: 1Exploit Tool / Code · 2026-03-04: 4Exploit Tool / Code · 2026-03-06: 3Exploit Tool / Code · 2026-03-09: 2Exploit Tool / Code · 2026-03-11: 1Exploit Tool / Code · 2026-03-12: 2Exploit Tool / Code · 2026-04-10: 1Exploit Tool / Code · 2026-05-01: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-06-27: 1Active Exploitation · 2026-02-25: 40Active Exploitation · 2026-02-26: 98Active Exploitation · 2026-02-27: 27Active Exploitation · 2026-02-28: 5Active Exploitation · 2026-03-01: 5Active Exploitation · 2026-03-02: 16Active Exploitation · 2026-03-03: 6Active Exploitation · 2026-03-04: 8Active Exploitation · 2026-03-05: 13Active Exploitation · 2026-03-06: 9Active Exploitation · 2026-03-07: 5Active Exploitation · 2026-03-08: 5Active Exploitation · 2026-03-09: 8Active Exploitation · 2026-03-10: 5Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-12: 4Active Exploitation · 2026-03-13: 2Active Exploitation · 2026-03-14: 2Active Exploitation · 2026-03-16: 3Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-15: 5Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-09: 3Active Exploitation · 2026-06-14: 2Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-09-15: 1Patch / Workaround · 2026-02-25: 15Patch / Workaround · 2026-02-26: 39Patch / Workaround · 2026-02-27: 11Patch / Workaround · 2026-02-28: 2Patch / Workaround · 2026-03-01: 4Patch / Workaround · 2026-03-02: 4Patch / Workaround · 2026-03-03: 4Patch / Workaround · 2026-03-04: 6Patch / Workaround · 2026-03-05: 7Patch / Workaround · 2026-03-06: 6Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-08: 5Patch / Workaround · 2026-03-09: 4Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-12: 3Patch / Workaround · 2026-03-13: 3Patch / Workaround · 2026-03-14: 5Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-15: 3Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-02-25: 31Technical Details · 2026-02-26: 76Technical Details · 2026-02-27: 18Technical Details · 2026-02-28: 8Technical Details · 2026-03-01: 6Technical Details · 2026-03-02: 12Technical Details · 2026-03-03: 7Technical Details · 2026-03-04: 6Technical Details · 2026-03-05: 9Technical Details · 2026-03-06: 9Technical Details · 2026-03-07: 3Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 6Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 4Technical Details · 2026-03-13: 4Technical Details · 2026-03-14: 4Technical Details · 2026-03-16: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-18: 3Technical Details · 2026-05-24: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-05: 2Technical Details · 2026-06-06: 1Technical Details · 2026-06-09: 2Technical Details · 2026-06-17: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-02: 102-2503-0203-0703-1203-1804-0304-1705-0105-1606-0606-2509-15
Signal classification7 categories
Active Exploitation
28067.3%
General
4711.3%
Disclosure
358.4%
Patch
348.2%
PoC
102.4%
Exploit
92.2%
Referenced assets278 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-2549
Active Exploitation39Disclosure4General4Patch2
2026-02-26116
Active Exploitation95Disclosure8General9Patch4
2026-02-2738
Active Exploitation26Disclosure3General5Patch4
2026-02-2815
Active Exploitation5Disclosure4General4PoC2
2026-03-019
Active Exploitation5Disclosure1General2Patch1
2026-03-0225
Active Exploitation14Disclosure6Exploit1General2Patch2
2026-03-0310
Active Exploitation5Disclosure1General2Patch2
2026-03-0412
Active Exploitation6Disclosure1Exploit1General1Patch1PoC2
2026-03-0516
Active Exploitation12General2Patch2
2026-03-0617
Active Exploitation7Exploit1General3Patch3PoC3
2026-03-076
Active Exploitation5General1
2026-03-086
Active Exploitation5Patch1
2026-03-099
Active Exploitation6Exploit1Patch1PoC1
2026-03-107
Active Exploitation4Disclosure1Exploit1General1
2026-03-115
Active Exploitation1Exploit1General2PoC1
2026-03-128
Active Exploitation4Exploit1General2PoC1
2026-03-137
Active Exploitation2Disclosure1General2Patch2
2026-03-145
Active Exploitation2Patch3
2026-03-163
Active Exploitation3
2026-03-171
Patch1
2026-03-182
Active Exploitation1Patch1
2026-03-211
Disclosure1
2026-03-232
Active Exploitation1Patch1
2026-03-271
Active Exploitation1
2026-04-011
Active Exploitation1
2026-04-032
Active Exploitation1General1
2026-04-101
Exploit1
2026-04-111
Active Exploitation1
2026-04-131
Patch1
2026-04-152
Active Exploitation2
2026-04-171
False Positive1
2026-04-201
General1
2026-04-212
Active Exploitation2
2026-04-221
Disclosure1
2026-04-231
General1
2026-05-011
Active Exploitation1
2026-05-052
Active Exploitation1Disclosure1
2026-05-121
Active Exploitation1
2026-05-141
Active Exploitation1
2026-05-155
Active Exploitation4Patch1
2026-05-161
Active Exploitation1
2026-05-183
Active Exploitation1Disclosure2
2026-05-241
Active Exploitation1
2026-06-011
General1
2026-06-052
Active Exploitation2
2026-06-061
Active Exploitation1
2026-06-071
Active Exploitation1
2026-06-093
Active Exploitation3
2026-06-142
Active Exploitation2
2026-06-171
Patch1
2026-06-251
Active Exploitation1
2026-06-261
Active Exploitation1
2026-06-271
Exploit1
2026-07-021
Active Exploitation1
2026-07-181
General1
2026-09-151
Active Exploitation1
Full discourse20 posts
  • FBI Cyber Division@FBICyberDiv
    Active Exploitation

    🚨 Malicious cyber actors are targeting and compromising Cisco SD-WAN systems deployed by organizations worldwide. These actors have exploited a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems. The FBI urges network defenders to fully patch Cisco SD-WAN systems and hunt for evidence of compromise. Find info and resources from @CISACyber 👉 https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-and-partners-release-guidance-ongoing-global-exploitation-cisco-sd-wan-systems

    Post summary

    Malicious actors are actively exploiting an authentication bypass in Cisco SD‑WAN (CVE‑2026‑20127) and escalating privileges with CVE‑2022‑20775; the FBI urges immediate patching and investigation.

    31151113636928.6K
    2.9K followersView on X
  • Stephen Fewer@stephenfewer
    Active Exploitation

    Today @rapid7 and Cisco are disclosing CVE-2026-20182, a critical (CVSS 10.0) auth bypass affecting Cisco Catalyst SD-WAN Controller, found by @_CryptoCat and I when we were researching CVE-2026-20127 last Feb. An unauth attacker can become the vmanage-admin and issue arbitrary NETCONF commands. Cisco has also disclosed that the new CVE is already EITW as of this month. Read our blog here with full technical details: https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/

    Post summary

    Rapid7 and Cisco disclose CVE-2026-20182, a CVSS 10.0 authentication bypass in Cisco Catalyst SD‑WAN Controller, and confirm it is already exploited in the wild, providing a link to a blog with detailed technical information.

    790628611771.6K
    9.8K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    🚨 Cisco and cyber agencies warn a critical 10.0 Cisco SD-WAN flaw (CVE-2026-20127) was exploited in zero-day attacks since at least 2023. Attackers used it to compromise controllers and add malicious rogue peers to targeted networks. ➡️Learn more: https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/

    Post summary

    Cisco SD‑WAN flaw CVE‑2026‑20127 has been actively exploited in zero‑day attacks since 2023, allowing attackers to compromise controllers and insert rogue peers into targeted networks.

    97252327726.9K
    248.5K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🚨 Cyber threat actors are exploiting multiple Cisco vulnerabilities, including CVE-2026-20127 and CVE-2022-20775, to ultimately establish long-term persistence in SD-WAN systems across multinational organizations. Review our Alert & act immediately. 👉 https://go.dhs.gov/iHw https://t.co/ktTANz3875

    Post summary

    Threat actors are actively exploiting Cisco CVE-2026-20127 and CVE-2022-20775 to gain long‑term persistence in SD‑WAN systems, prompting immediate action.

    56241624718.4K
    292.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Cisco is warning of active exploitation of a CVSS 10.0 flaw in Catalyst SD-WAN controllers. CVE-2026-20127 lets unauthenticated attackers bypass auth and gain admin access. Exploitation tied to UAT-8616 dates back to 2023, including rogue peers in the control plane and root escalation. 🔗 Read → https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html

    Post summary

    Cisco warns of active exploitation of CVE-2026-20127, a CVSS 10.0 flaw that lets unauthenticated attackers bypass authentication and gain admin/root access on Catalyst SD‑WAN controllers.

    83911261939.0K
    1.0M followersView on X
  • CryptoCat@_CryptoCat
    Active Exploitation

    🚨 CVE-2026-20127: Cisco SD-WAN authentication bypass. An unauthenticated attacker can inject SSH keys without crypto verification via a flawed state machine. Active exploitation by UAT-8616 since 2023 💀 Check out the full @rapid7 analysis 👇 https://attackerkb.com/topics/bP3FMvHe7z/cve-2026-20127/rapid7-analysis

    Post summary

    The tweet reports that CVE-2026-20127 is actively exploited since 2023, allowing unauthenticated attackers to inject SSH keys via a flawed state machine.

    4283963819.6K
    8.5K followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    Unit 42 is tracking CVE-2026-20127, an actively exploited zero-day vuln in Cisco Catalyst SD-WAN Controller. We recommend updating to the latest versions, hunting for signs of compromise and reviewing the Talos Threat Advisory here: https://bit.ly/46uYApr https://t.co/L2AhJtbgYG

    Post summary

    Unit 42 reports that CVE-2026-20127 is an actively exploited zero‑day vulnerability in Cisco Catalyst SD‑WAN Controller and urges users to update to the latest versions and monitor for compromise.

    227169207.8K
    66.8K followersView on X
  • CryptoCat@_CryptoCat
    PoC

    @rapid7 PoC from @stephenfewer 🔥 https://github.com/sfewer-r7/CVE-2026-20127

    Post summary

    Rapid7 shares a Proof of Concept for CVE‑2026‑20127, linking to a GitHub repository that likely contains the exploit code.

    051684371.3K
    8.5K followersView on X
  • watchTowr@watchtowrcyber
    Active Exploitation

    🚨 watchTowr is rapidly reacting to CVE-2026-20127, a critical auth bypass in Cisco’s Catalyst SD-WAN Controller with active in-the-wild exploitation reported. Patch urgently. Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support.

    Post summary

    CVE-2026-20127 is an auth bypass in Cisco Catalyst SD-WAN Controller that is actively exploited in the wild; urgent patching is advised for affected watchTowr Platform clients.

    220267267.8K
    11.0K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Cisco SD-WAN CVE-2026-20127 is under active exploitation by multiple attackers Exploit activity is decently heavy with attackers trying to implement multiple persistence mechanisms Attacker in screenshot implements a gsocket/gs-netcat based backdoor connected to a Telegram bot, using kernel thread name spoofing ([kswapd0], [ksmd]) to hide processes. Patch immediately. If on an affected version, assume compromise and hunt. Track exploitation 👉 https://console.defusedcyber.com/intel

    Post summary

    The post reports that CVE‑2026‑20127 is actively being exploited by attackers using a gsocket/gs‑netcat backdoor, and urges immediate patching. No PoC or detailed technical data are offered beyond the tool mention and exploit technique.

    4222573117.8K
    6.1K followersView on X
  • Simo@SimoKohonen
    Active Exploitation

    Webshells be flowing into Cisco SD-WAN honeypots now.. Exploitation of CVE-2026-20127 is looking pretty heavy, new actors popping up by the hour https://t.co/rO3gxeNr7h

    Post summary

    The tweet reports that CVE-2026-20127 is being actively exploited in the wild, with new attackers emerging frequently.

    2191652015.7K
    2.9K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Cisco Catalyst SD-WAN path traversal vulnerability CVE-2022-20775 & Controller and Manager authentication bypass vulnerability CVE-2026-20127 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. https://t.co/ZicRI3q7Ph

    Post summary

    The tweet announces that two Cisco vulnerabilities have been added to the DHS KEV catalog, indicating they are actively exploited, and urges applying mitigations.

    22005588.3K
    292.1K followersView on X
  • Metasploit Project@metasploit
    Exploit

    This week's release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/

    Post summary

    Rapid7 announced new Metasploit modules that include functional exploit code for CVE-2026-20127 and CVE-2026-22200, marking them as available for use within the exploit framework.

    012045164.8K
    253.4K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨Two Cisco Catalyst SD-WAN Controller vulns added to CISA KEV today CVE-2026-20127 (auth bypass) and CVE-2022-20775 (path traversal) are actively being exploited in the wild by nation-state actor UAT-8616 since 2023. No public PoC exists for either - we've added a Cisco SD-WAN honeypot stream to catch exploitation attempts🍯 http://console.defusedcyber.com/signup

    Post summary

    Two Cisco SD‑WAN Controller vulnerabilities (CVE‑2026‑20127 and CVE‑2022‑20775) are being actively exploited by a nation‑state actor; no public PoC or patch is available, but a honeypot is deployed to detect attacks.

    315140148.4K
    6.1K followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Active Exploitation

    Overnight we observed the first exploitation attempts against Cisco Catalyst SD-WAN in our honeypots. Activity started around 03:00 UTC, leveraging the now-public PoC. CVE-2026-20127 If you're running SD-WAN and haven't patched yet, now would be a good time. @watchtowrcyber

    Post summary

    Multiple honeypots recorded the first real-world exploit attempts against Cisco Catalyst SD-WAN using CVE-2026-20127, leveraging a now-public PoC. Immediate patching is recommended.

    015041127.6K
    21.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ CVE-2026-20127: Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access. PoC: https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE "This repository contains a working proof-of-concept exploit for CVE-2026-20127, a critical pre-authentication vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage) that has been actively exploited in the wild since 2023."

    Post summary

    A publicly posted PoC exploit for CVE-2026-20127 demonstrates a critical pre‑authentication vulnerability in Cisco SD‑WAN controllers that has been actively exploited in the wild since 2023.

    19036196.0K
    171.6K followersView on X
  • Defused@DefusedCyber
    General

    ⚠️Cisco SD-WAN (CVE-2026-20127) enumeration slowly on the increase We have observed fingeprinting attempts against vulnerable Cisco SD-WAN instances - involving either utilizing Nuclei templates for older CVE's (such as CVE-2020–26073) or probing various SD-WAN REST API authentication endpoints. No observed POC candidates as of yet Some IPs involved from the past 24 hours: 111.194.48.235 China Unicom Beijing Province 🇨🇳 158.174.210.97 Bahnhof AB 🇸🇪 95.215.0.144 Petersburg Internet Network ltd. 🇷🇺

    Post summary

    The post reports increased enumeration attempts against Cisco SD-WAN instances for CVE-2026-20127, with no PoC or exploit code observed, and no patch or technical details provided.

    113133105.2K
    6.1K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-20127(Zero-Day, CVSS 10.0): Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 📊 3.6K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cisco%20Catalyst%20SD-WAN%22 👇Query HUNTER : http://product.name="Cisco Catalyst SD-WAN" 📰Refer:https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces a newly identified zero‑day authentication bypass vulnerability (CVE‑2026‑20127) in Cisco Catalyst SD‑WAN Controller with a CVSS score of 10.0, providing links to a security advisory and an external news article but no exploit or mitigation details.

    38023132.3K
    25.4K followersView on X
  • ANSSI@ANSSI_FR
    Active Exploitation

    ⚠️ Vulnérabilité Cisco Catalyst SD-WAN. 📢 Le @CERT_FR a publié un bulletin d'alerte concernant la vulnérabilité activement exploitée CVE-2026-20127, affectant Cisco Catalyst SD-WAN. ➡️ + d'infos sur le site du CERT-FR : https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-002/ https://t.co/QxjAz9zl3x

    Post summary

    CERT‑FR has issued an alert that CVE‑2026‑20127 is actively exploited against Cisco Catalyst SD‑WAN, but no PoC, exploit code, patch, or technical details are provided.

    01402225.0K
    83.4K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-20127: Vulnerability Alert Critical Remote Code Execution via SD-WAN Orchestrator API Deserialization! An attacker sends a maliciously crafted serialized Java object in an authenticated API request to the Cisco vManage orchestrator, triggering unsafe deserialization that executes arbitrary code with root privileges on the underlying Linux system. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-20127 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-20127" Search Dork: app="Cisco Catalyst SD-WAN" Exposure: 2k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJDaXNjbyBDYXRhbHlzdCBTRC1XQU4i&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260302 #Cisco #RCE #Deserialization #SDWAN #ZeroDay #DarkEye

    Post summary

    The tweet announces CVE-2026-20127 as a critical RCE via unsafe Java deserialization in Cisco SD‑WAN vManage, providing links for analysis and target identification but no PoC, exploit tool, or evidence of active exploitation.

    0801732.0K
    11.9K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.6--
Appciscosd-wan_vbond_orchestrator---
Appciscosd-wan_vbond_orchestrator20.12.6--
Appciscosd-wan_vsmart_controller---
Appciscosd-wan_vsmart_controller20.12.6--

Explore more