Junglewise Threat Intelligence

CVE-2026-20127: Cisco Catalyst SD-WAN auth bypass in peering authentication

CVE-2026-20127 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-02-25

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

A critical vulnerability in Cisco's SD-WAN management software allows unauthorized individuals to bypass security checks and gain administrative control over the network. Cisco Catalyst SD-WAN is used by organizations to manage and secure large-scale corporate networks. An attacker exploiting this flaw could remotely log into the system, change network configurations, and potentially disrupt all communications across the business infrastructure.

Technical details

This vulnerability (CWE-287) stems from a failure in the peering authentication mechanism used between Cisco Catalyst SD-WAN Controllers, Managers, and Validators. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected system's peering interface. Successful exploitation grants access as a high-privileged, non-root internal user account. From this position, the attacker can access the NETCONF interface to manipulate the network configuration of the entire SD-WAN fabric. Cisco has released software updates to address the issue, and CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation.

Affected products

  • Cisco Catalyst SD-WAN Controller (vSmart) All versions prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, 20.18.2.1
  • Cisco Catalyst SD-WAN Manager (vManage) All versions prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, 20.18.2.1
  • Cisco Catalyst SD-WAN Validator (vBond) All versions prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, 20.18.2.1

Timeline

  • 2026-02-25: advisory: Initial advisory published by Cisco
  • 2026-02-25: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2026-06-16: other: Advisory updated to include Catalyst SD-WAN Validator (vBond)

References

Related threats