
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20127 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows unauthenticated remote attackers to obtain administrative privileges. The vulnerability was publicly disclosed on February 25, 2026, and was already being actively exploited as a zero-day at the time of disclosure — with evidence of exploitation dating back to at least 2023. Affected versions include SD-WAN vSmart Controller and Catalyst SD-WAN Manager releases prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.2.1. It carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory, CISA KEV).
The vulnerability is classified as CWE-287 (Improper Authentication) and stems from a flaw in the peering authentication mechanism used between SD-WAN control components. The peering authentication process fails to properly validate incoming connection requests, allowing an attacker to send crafted requests that are accepted as legitimate peer connections. A successful exploit grants the attacker login access to the Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account (vmanage-admin). From this foothold, the attacker can access NETCONF (port 830), enabling full manipulation of SD-WAN fabric network configurations. The attack requires no authentication, no user interaction, and no special preconditions beyond network reachability to the affected control components — particularly ports 22 and 830 (Cisco Advisory, Rapid7 ETR).
Successful exploitation allows an unauthenticated remote attacker to gain high-privileged access to the Cisco Catalyst SD-WAN Controller and Manager, with full NETCONF access to manipulate SD-WAN fabric configurations across the entire enterprise network. This enables attackers to alter routing policies, intercept or redirect traffic, establish persistent backdoor peer connections, and potentially pivot to connected network segments. The scope is marked as "Changed" in the CVSS scoring, reflecting that a compromise of the SD-WAN controller can impact the confidentiality, integrity, and availability of the broader network fabric beyond the directly affected system. Threat actor UAT-8616 leveraged this vulnerability to gain persistent access to critical infrastructure targets over a multi-year campaign (Cisco Talos, Cisco Advisory).
vmanage-admin high-privileged account./var/log/auth.log showing Accepted publickey for vmanage-admin from an unknown or unauthorized IP address — cross-reference the source IP against known/configured System IPs in the SD-WAN Manager web UI.peer-type:vmanage from unrecognized public-ip addresses or at unusual times (e.g., %Viptela-vSmart-VDAEMON_0-5-NTCE-1000001: control-connection-state-change new-state:up peer-type:vmanage peer-system-ip:<unexpected IP>).vmanage-admin account not correlated with authorized change management activity (Cisco Advisory, CISA KEV).Cisco has released fixed software versions: 20.9.8.2, 20.12.5.3 (and 20.12.6.1), 20.15.4.2, and 20.18.2.1. Upgrading to a fixed release is the only complete remediation — no workarounds fully address the vulnerability (Cisco Advisory). As a temporary mitigation for on-premises deployments, Cisco recommends applying ACLs, security group rules, or firewall rules to restrict access to ports 22 and 830 to only known, trusted controller IPs and authorized hosts. For Cisco Hosted SD-WAN Cloud environments, guardrails are already in place. CISA Emergency Directive ED-26-03 mandated federal agencies patch by February 27, 2026. Organizations should also audit /var/log/auth.log for signs of prior compromise and review all control-connection peering events for unauthorized entries (CISA KEV).
The disclosure triggered immediate, widespread response from government agencies and the security community. CISA issued Emergency Directive ED-26-03 with a 48-hour remediation deadline for federal agencies — one of the shortest ever issued — and published joint guidance with Five Eyes partners (NSA, FBI, ACSC, NCSC, CCCS) (NSA Press Release). Cisco Talos published a detailed threat intelligence report attributing the three-year exploitation campaign to UAT-8616, describing it as a sophisticated, persistent threat actor targeting critical infrastructure (Cisco Talos). Security researchers at Rapid7, Tenable, Sophos, and Horizon3.ai published technical analyses and detection guidance. The revelation that the vulnerability had been exploited since at least 2023 without detection generated significant concern in the security community, with coverage from BleepingComputer, Dark Reading, The Register, CyberScoop, and SecurityWeek highlighting the severity and the broader pattern of Cisco SD-WAN vulnerabilities being exploited in 2026 (BleepingComputer, Tenable Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."