CISA and International Partners Warn of Major Cisco SD-WAN Vulnerability

By

Check the alert for recommended actions.

The US Cybersecurity and Infrastructure Security Agency (CISA), along with international partner agencies, has issued an alert regarding active compromise of Cisco Catalyst SD-WAN systems.

According to the statement, malicious actors “have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.”

The alert strongly urges network defenders to immediately:

  1. Inventory all in-scope Cisco SD-WAN systems.
  2. Collect artifacts, including virtual snapshots and logs of SD-WAN systems to support threat hunt activities.
  3. Fully patch Cisco SD-WAN systems with available updates.
  4. Hunt for evidence of compromise.
  5. Concurrently review Cisco’s latest security advisories and implement Cisco’s SD-WAN Hardening Guidance.

CISA has also issued the following directives to help address malicious activity involving vulnerable Cisco SD-WAN systems:

Read more at CISA.
 
 

 
 
 

03/03/2026
comments powered by Disqus
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs



Support Our Work

ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.

Learn More”>
	</a>

<hr>		    
			</div>
		    		</div>

		<div class=