Skip to content
English

Patch first › Cisco

Exploited

CVE-2026-20127

Cisco Catalyst SD-WAN · Switches, routers and SD-WAN

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

At a glance

Exploited. Added to CISA’s catalog of exploited vulnerabilities on February 25, 2026.

Affected product: Cisco Catalyst SD-WAN (category Switches, routers and SD-WAN, indicative classification). Name in CISA’s catalog: Cisco Catalyst SD-WAN Controller and Manager.

What should I do?

CISA has issued specific instructions for this vulnerability: read the original text and the NVD entry.

Deadline set by CISA for US federal agencies: 2 days (due February 27, 2026). It only binds those agencies, but it is a useful measure of urgency.

Original text of the required action (CISA)

Please adhere to CISA's guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA's Emergency Directive 26-03 (URL listed below in Notes) and CISA's "Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Timeline

  1. Vulnerability published Publication date (NVD)
  2. Exploitation confirmed Added to CISA’s KEV catalog
  3. CISA deadline Remediation deadline set for US federal agencies

The facts, with their sources

Exploitation confirmed
Yes, on February 25, 2026 Date added to the catalog of exploited vulnerabilities. Exploitation itself may have started earlier. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
Ransomware
No known use to date That does not guarantee it is not being used: the information is not public. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
Hunt for compromise
Not requested by CISA Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
CISA required action
CISA has issued specific instructions for this vulnerability: read the original text and the NVD entry. Rewritten by this site from CISA’s original text. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
CISA deadline
February 27, 2026, 2 days Set for US federal agencies: a measure of urgency, not an obligation elsewhere. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
Vulnerability published
February 25, 2026 Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
Product according to CISA
Cisco Catalyst SD-WAN Controller and Manager Filed by this site under “Switches, routers and SD-WAN” (indicative classification). Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Technical detail of the score: attack vector, complexity, impact. Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC

Severity and activity

10.0 / 10 CVSS severity: critical

Score from the NVD. Collected Sep 29, 2026.

— Probability of exploitation in the next 30 days (EPSS)

FIRST’s EPSS model. Since exploitation is already confirmed, this figure is mostly useful to compare activity. Collected Sep 29, 2026.

Description

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

Official description from the NVD, collected Sep 29, 2026. CVE® description © The MITRE Corporation.

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Summary from CISA (KEV catalog).

CERT-FR advisories

  • CERTFR-2026-ALE-002: [MàJ] Vulnérabilité dans Cisco Catalyst SD-WAN (updated March 26, 2026)

Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.

Sources for this page

  • CISA KEV catalog: exploitation, date added, required action, deadline, ransomware.
  • NVD (NIST): CVSS severity, publication date, description, vendor references.
  • EPSS (FIRST): probability of exploitation.
  • CERT-FR: advisories and alerts (in French).
  • Brand and category: indicative classification by this site (method).