FBI Cyber Division[verified]@FBICyberDivActive Exploitation
Malicious actors are actively exploiting an authentication bypass in Cisco SD‑WAN (CVE‑2026‑20127) and escalating privileges with CVE‑2022‑20775; the FBI urges immediate patching and investigation.
BleepingComputer[verified]@BleepinComputerActive Exploitation
Cisco SD‑WAN flaw CVE‑2026‑20127 has been actively exploited in zero‑day attacks since 2023, allowing attackers to compromise controllers and insert rogue peers into targeted networks.
watchTowr[verified]@watchtowrcyberActive Exploitation
CVE-2026-20127 is an auth bypass in Cisco Catalyst SD-WAN Controller that is actively exploited in the wild; urgent patching is advised for affected watchTowr Platform clients.
Simo[verified]@SimoKohonenActive Exploitation
The tweet reports that CVE-2026-20127 is being actively exploited in the wild, with new attackers emerging frequently.
Metasploit Project[verified]@metasploitExploit
Rapid7 announced new Metasploit modules that include functional exploit code for CVE-2026-20127 and CVE-2026-22200, marking them as available for use within the exploit framework.
Hunter[verified]@HunterMappingDisclosure
The post announces a newly identified zero‑day authentication bypass vulnerability (CVE‑2026‑20127) in Cisco Catalyst SD‑WAN Controller with a CVSS score of 10.0, providing links to a security advisory and an external news article but no exploit or mitigation details.
ZoomEye[verified]@zoomeye_teamDisclosure
The tweet announces CVE-2026-20127 as a critical RCE via unsafe Java deserialization in Cisco SD‑WAN vManage, providing links for analysis and target identification but no PoC, exploit tool, or evidence of active exploitation.
Stephen Fewer@stephenfewerActive Exploitation
Rapid7 and Cisco disclose CVE-2026-20182, a CVSS 10.0 authentication bypass in Cisco Catalyst SD‑WAN Controller, and confirm it is already exploited in the wild, providing a link to a blog with detailed technical information.