Cisco Warns of Critical SD-WAN Security Vulnerability Open Since 2023


  • Cisco Catalyst SD-WAN zero-day (CVE-2026-20127) operating since 2023
  • A flaw allowed attackers to add malicious peers and manipulate network configurations.
  • CISA added a bug to the KEV catalog, ordering urgent fixes; linked to the UAT-8616 threat group

“Highly sophisticated” threat actors have allegedly exploited a zero-day vulnerability in Cisco Catalyst SD-WAN for more than two years, the company has revealed.

Cisco’s cybersecurity arm, Talos, has released a new report saying it observed a critical authentication vulnerability actively exploited by crooks who used it to compromise controllers and add malicious peers to target networks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top