Cisco warns of critical SD-WAN security flaws that have been open since 2023


  • Cisco Catalyst SD-WAN zero-day (CVE-2026-20127) has been exploited since 2023
  • Flaws allowed attackers to add rogue peers and manipulate network configurations
  • CISA added errors to the KEV catalog and ordered urgent corrections; linked to the threat group UAT-8616

“Highly sophisticated” threat actors have allegedly been exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN for over two years, the company has revealed.

Cisco’s cybersecurity arm, Talos, released a new report saying it observed a critical authentication vulnerability being actively exploited by bad guys who used it to compromise controllers and add malicious rogue peers to target networks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top