Five Eyes allies warn hackers are actively exploiting Cisco SD
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-20775 | Path Traversal Privilege Escalation in Cisco SD-WAN Software CLI CVE-2022-20775 is a path traversal and improper access control flaw (CWE-22/CWE-25) in the CLI of Cisco SD-WAN Software that allows an authenticated, local attacker to gain elevated privileges. An attacker triggers it by running a maliciously crafted command in the application CLI, abusing weak access controls on CLI commands. A successful exploit yields arbitrary command execution as the root user, giving full control of the affected SD-WAN component. Organizations running Cisco SD-WAN / Catalyst SD-WAN components — SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud routers — are affected. The flaw is now being actively exploited: it was added to the CISA KEV catalog on 2026-02-25, prompting CISA Emergency Directive 26-03 and joint Five Eyes 'Hunt & Hardening' guidance, a public proof-of-concept exists, and EPSS estimates a 12.5% chance of exploitation within 30 days (96th percentile). Do: Upgrade affected SD-WAN components — Catalyst SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud — to the fixed releases listed in Cisco advisory cisco-sa-sd-wan-priv-E6e8tEdF, as there are no workarounds. Restrict CLI access to trusted administrators, review local accounts for unexpected additions or changes, and hunt for signs of compromise per CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices. If patched software or cloud-service mitigations are unavailable, follow BOD 22-01 guidance and consider discontinuing use of the affected components. | 7.8 | 12% | KEV PoC |
| largeon the order of tens of thousands of SD-WAN controller and edge deployments (10k–100k systems) | |
| CVE-2026-20127 | Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile). Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product. | 10.0 | 88% | KEV |
| large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise… |
Full article459 words · extracted from therecord.media · click to collapse
Cybersecurity agencies from the Five Eyes intelligence alliance urgently warned Wednesday that “an advanced threat actor” is actively exploiting new flaws in Cisco networking equipment, pressing organizations to look for signs their systems may already have been compromised. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive warning of a “cyber threat actor’s ongoing exploitation of Cisco SD-WAN systems,” describing the activity as presenting a significant risk to federal civilian executive branch networks. The vulnerabilities cited in the alerts include CVE-2026-20127 and CVE-2022-20775, which have been linked to real-world exploitation. CISA said it has assessed that the conditions pose “an unacceptable risk to federal agencies and necessitate emergency action.” The British National Cyber Security Centre (NCSC) also said “malicious cyber threat actors are targeting Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) used by organisations globally,” underscoring that the activity is not limited to the United States. The NCSC’s chief technology officer, Ollie Whitehouse, said organizations using the affected Cisco products “should urgently investigate their exposure to network compromise” and start to hunt for evidence that a compromise has taken place. Cisco’s own advisory warns “multiple vulnerabilities” in its product “could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files.” The company stressed the vulnerabilities “are not dependent on one another” and that exploitation of one of the vulnerabilities is not required to exploit another. As part of the joint alert, the Australian Signals Directorate, the country’s cyber and signals intelligence agency, published a technical “hunt guide” to help organizations understand whether hackers are already inside their systems. According to the guide, at least one malicious cyber actor has been compromising Cisco SD-WAN environments since 2023 using a zero-day vulnerability that was identified late last year and has since been patched. “The vulnerability allowed a malicious cyber actor to create a rogue peer joined to the network management plane, or control plane, of an organisation’s SD-WAN,” the document says. “The rogue device appears as a new but temporary, actor-controlled SD-WAN component that can conduct trusted actions within the management and control plane.” The hunt guide describes how attackers who gained this level of access were able to establish long-term persistence, including by obtaining root access and taking steps to evade detection, such as interfering with logging and other monitoring. The agencies have not publicly identified the threat groups believed to be behind the activity.
No previous article
No new articles
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan