2026-002: Multiple Vulnerabilities in Cisco Products
Cisco fixed SD-WAN Controller auth bypass CVE-2026-20127 (CVSS 10) exploited in the wild since 2023, plus several critical and high flaws in SD-WAN Manager.
On 25 February 2026 Cisco released advisories for multiple flaws in Catalyst SD-WAN Controller and SD-WAN Manager, potentially granting administrative access to attackers. CVE-2026-20127 (CVSS 10.0) is an authentication bypass in the Controller's peering authentication mechanism, exploited in the wild since 2023, allowing unauthenticated admin access via NETCONF, rogue device injection, and persistent access. SD-WAN Manager flaws include CVE-2026-20129 (9.8, unauthenticated API auth bypass to netadmin), CVE-2026-20126 (7.8, local privesc to root), CVE-2026-20133 (7.5, info disclosure), CVE-2026-20122 (7.1, arbitrary file overwrite), and CVE-2026-20128 (5.5, DCA info disclosure). CERT-EU recommends patching, capturing forensic evidence, IOC hunting, and restricting management-plane internet exposure.
- CVE-2026-20127 (CVSS 10): SD-WAN Controller auth bypass to admin, exploited in the wild since 2023
- CVE-2026-20129 (CVSS 9.8): unauthenticated API auth bypass in SD-WAN Manager
- Other flaws: root privesc (7.8), info disclosure (7.5/5.5), file overwrite (7.1)
- Exploitation enables rogue SD-WAN devices, config changes, and persistent access
- Cisco and CERT-EU advise forensic evidence capture, IOC hunting, and patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20122 | Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown. Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable. | 5.4 | 25% | KEV |
| large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide | |
| CVE-2026-20133 | Actively Exploited Information Disclosure in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager, the central management and monitoring platform for Cisco SD-WAN fabrics (formerly known as vManage), contains a sensitive-information-exposure flaw (CWE-200) that allows remote attackers to view sensitive information on affected systems. The available data does not specify the exact trigger path or authentication requirements, but the flaw is remotely exploitable by unauthorized actors. An attacker gains access to sensitive information held on the management platform, which aggregates inventory, configuration, and telemetry for an entire SD-WAN overlay, potentially aiding follow-on attacks. Any organization running an affected release of Cisco Catalyst SD-WAN Manager is in scope. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-04-20, confirming exploitation in the wild, and EPSS assigns a 31.4% probability of exploitation within 30 days (98th percentile), although CVSS scoring is pending and no public proof-of-concept is known. Do: Inventory your environment for internet-exposed Catalyst SD-WAN Manager instances and review access logs for signs of unauthorized retrieval of sensitive information, since the flaw is listed as exploited in the wild. Apply the vendor fix referenced in Cisco's advisory for CVE-2026-20133 when available, and follow CISA's Emergency Directive 26-03 and the CISA 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'; federal agencies must adhere to applicable BOD 22-01 mitigation timelines or discontinue use of the product if mitigations are unavailable. | 7.5 group max | 31% | KEV |
| large≈tens of thousands of deployments (Cisco has publicly cited 30,000+ SD-WAN customers, each operating at least one Manager controller) | |
| CVE-2026-20127 | Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile). Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product. | 10.0 | 88% | KEV |
| large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 20.12.5.3 | end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.1 |
| ipv4 | 20.12.6.1 | s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers |
| ipv4 | 20.15.4.2 | (end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all vers |
| ipv4 | 20.9.8.2 | 9 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all vers |
Full article1,157 words · extracted from cert.europa.eu · click to collapse
History:
- 25/02/2026 --- v1.0 -- Initial publication
Summary
On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager [1,2]. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems.
It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon as possible.
One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023. [4]
Technical Details
Vulnerabilities Affecting Cisco Catalyst SD-WAN Controller
The vulnerability CVE-2026-20127, with the CVSS score of 10, is an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vManager. Successful exploitation allows a remote, unauthenticated attacker to obtain administrative privileges on the device. [1]
An attacker could then modify configurations, add rogue devices to the SD-WAN fabric, extract sensitive configuration data, or establish persistent access. [1]
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. [1]
Vulnerabilities Affecting Cisco Catalyst SD-WAN Manager
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files. [2]
The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability.
The vulnerability CVE-2026-20129, with a CVSS score of 9.8, is an authentication bypass vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. [2]
The vulnerability CVE-2026-20126, with a CVSS score of 7.8, is a privilege escalation vulnerability which could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system. [2]
The vulnerability CVE-2026-20133, with a CVSS score of 7.5, is an information disclosure vulnerability which could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. [2]
The vulnerability CVE-2026-20122, with a CVSS score of 7.1, is an arbitrary file overwrite vulnerability in the API which could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. [2]
The vulnerability CVE-2026-20128, with a CVSS score of 5.5, is an information disclosure vulnerability in the Data Collection Agent (DCA) feature which could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the file system as a low-privileged user and reading the file that contains the DCA password from that affected system. [2]
Affected Products
The following versions of the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager are affected:
- all versions earlier than 20.9 (end of software maintenance);
- all versions 20.9 up until 20.9.8.2;
- all versions 20.11 (end of software maintenance);
- all versions 20.12.5 up until 20.12.5.3;
- all versions 20.12.6 up until 20.12.6.1;
- all versions 20.13 (end of software maintenance);
- all versions 20.14 (end of software maintenance);
- all versions 20.15 up until 20.15.4.2;
- all versions 20.16 (end of software maintenance);
- all versions 20.18 up until 20.18.2.1.
Organisations are encouraged to consult the Cisco Catalyst SD-WAN Upgrade Matrix.
Recommendations
CERT-EU recommends the following immediate actions:
- Securing forensic evidence to detect any signs of exploitation as well as reviewing SD-WAN configuration to find any unauthorised changes, following the hunting guide. [4]
- Update affected devices to the appropriate fixed latest version of Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller as detailed in their respective advisories. [1,2]
- Identify and restrict external access to SD-WAN management (HTTPS, SSH, API) and control plane interfaces. Remove direct internet exposure and limit access to dedicated management networks by following Cisco's hardening guide. [6]
The hunting guide [4] further notes that, in observed exploitation cases, threat actors downgraded SD-WAN Manager to a software version vulnerable to CVE-2022-20775 in order to facilitate privilege escalation and establish persistence by creating local accounts. [3,4]
If a compromise is suspected, and after ensuring that forensic evidence is secured, contact the relevant cybersecurity authority.
Indicators of Compromise
Organisations are encouraged perform the following checks to identify possible exploitation of the vulnerability CVE-2026-20127:
- Audit authentication logs in the auth.log file, located at /var/log/auth.log, for entries that are related to Accepted publickey for vmanage-admin from unknown or unauthorised IP addresses, as shown in the following example:
2026-02-10T22:51:36+00:00 vm sshd[804]: Accepted publickey for vmanage-admin from port [REDACTED PORT] ssh2: RSA SHA256:[REDACTED KEY] - Validate peering events against the following checklist:
- Verify the timestamp of each peering event against known maintenance windows, scheduled configuration changes, and normal operational hours.
- Confirm the public IP address corresponds to infrastructure owned or operated by authorised organisation or partners by cross-referencing against asset inventories and authorised IP ranges.
- Validate that the peer system IP matches documented device assignments within the SD-WAN topology.
- Review the peer type (vmanage, vsmart, vedge, vbond) to ensure it aligns with expected device roles in the related deployment.
- Correlate multiple events from the same source IP or system IP to identify patterns of reconnaissance or persistent access attempts.
- Cross-reference event timing with authentication logs, change management records, and user activity to establish whether the connection was initiated by authorised personnel.
Jul 26 22:03:33 vSmart-01 VDAEMON_0[2571]: %Viptela-vSmart-VDAEMON_0-5-NTCE-1000001: control-connection-state-change new-state:up peer-type:vmanagepeer-system-ip:[PRIVATE IP] public-ip:[PUBLIC IP] public-port:[PUBLIC PORT] domain-id:1 site-id:1005 More information and indicators of compromise are available in the hunting guide. [4]
References
[3] https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sd-wan-priv-E6e8tEdF.html
[4] https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf
[5] https://www.ncsc.gov.uk/news/exploitation-cisco-catalyst-sd-wans
[6] https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide
Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-002/