CVE-2026-20127
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20127 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows unauthenticated remote attackers to obtain administrative privileges. The vulnerability was publicly disclosed on February 25, 2026, and was already being actively exploited as a zero-day at the time of disclosure — with evidence of exploitation dating back to at least 2023. Affected versions include SD-WAN vSmart Controller and Catalyst SD-WAN Manager releases prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.2.1. It carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication) and stems from a flaw in the peering authentication mechanism used between SD-WAN control components. The peering authentication process fails to properly validate incoming connection requests, allowing an attacker to send crafted requests that are accepted as legitimate peer connections. A successful exploit grants the attacker login access to the Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account (vmanage-admin). From this foothold, the attacker can access NETCONF (port 830), enabling full manipulation of SD-WAN fabric network configurations. The attack requires no authentication, no user interaction, and no special preconditions beyond network reachability to the affected control components — particularly ports 22 and 830 (Cisco Advisory, Rapid7 ETR).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain high-privileged access to the Cisco Catalyst SD-WAN Controller and Manager, with full NETCONF access to manipulate SD-WAN fabric configurations across the entire enterprise network. This enables attackers to alter routing policies, intercept or redirect traffic, establish persistent backdoor peer connections, and potentially pivot to connected network segments. The scope is marked as "Changed" in the CVSS scoring, reflecting that a compromise of the SD-WAN controller can impact the confidentiality, integrity, and availability of the broader network fabric beyond the directly affected system. Threat actor UAT-8616 leveraged this vulnerability to gain persistent access to critical infrastructure targets over a multi-year campaign (Cisco Talos, Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-exposed Cisco Catalyst SD-WAN Controller or Manager instances using tools like Shodan or Censys, targeting open ports 22 (SSH) and 830 (NETCONF). Focus on systems running vulnerable versions prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, or 20.18.2.1.
  2. Craft malicious peering request: Construct a specially crafted SD-WAN peering authentication request that exploits the improper validation in the peering authentication mechanism. The request mimics a legitimate vManage peer connection.
  3. Send crafted request to target: Transmit the crafted request to the target SD-WAN Controller or Manager over the network. No credentials or prior access are required.
  4. Gain privileged session: The flawed authentication mechanism accepts the request, granting the attacker login access as the internal vmanage-admin high-privileged account.
  5. Access NETCONF interface: Using the obtained session, connect to the NETCONF interface (port 830) to interact with the SD-WAN fabric management plane.
  6. Manipulate SD-WAN configuration: Issue NETCONF RPC commands to alter routing policies, add unauthorized peer connections, exfiltrate configuration data, or establish persistent backdoor access across the SD-WAN fabric (Cisco Advisory, Rapid7 ETR, Metasploit Module).

Indicators of compromise

  • Logs: Entries in /var/log/auth.log showing Accepted publickey for vmanage-admin from an unknown or unauthorized IP address — cross-reference the source IP against known/configured System IPs in the SD-WAN Manager web UI.
  • Logs: Unexpected control-connection-state-change events in vSmart/vManage logs with peer-type:vmanage from unrecognized public-ip addresses or at unusual times (e.g., %Viptela-vSmart-VDAEMON_0-5-NTCE-1000001: control-connection-state-change new-state:up peer-type:vmanage peer-system-ip:<unexpected IP>).
  • Network: Unexpected inbound connections to ports 22 (SSH) or 830 (NETCONF) on SD-WAN Controller or Manager from external or unrecognized IP addresses.
  • Network: Unusual NETCONF session activity originating from unauthorized sources, particularly configuration modification RPCs.
  • Configuration: Unauthorized or unexpected SD-WAN peer entries, routing policy changes, or new control connections appearing in the SD-WAN fabric topology.
  • Process/Behavior: Unexpected administrative actions performed under the vmanage-admin account not correlated with authorized change management activity (Cisco Advisory, CISA KEV).

Mitigation and workarounds

Cisco has released fixed software versions: 20.9.8.2, 20.12.5.3 (and 20.12.6.1), 20.15.4.2, and 20.18.2.1. Upgrading to a fixed release is the only complete remediation — no workarounds fully address the vulnerability (Cisco Advisory). As a temporary mitigation for on-premises deployments, Cisco recommends applying ACLs, security group rules, or firewall rules to restrict access to ports 22 and 830 to only known, trusted controller IPs and authorized hosts. For Cisco Hosted SD-WAN Cloud environments, guardrails are already in place. CISA Emergency Directive ED-26-03 mandated federal agencies patch by February 27, 2026. Organizations should also audit /var/log/auth.log for signs of prior compromise and review all control-connection peering events for unauthorized entries (CISA KEV).

Community reactions

The disclosure triggered immediate, widespread response from government agencies and the security community. CISA issued Emergency Directive ED-26-03 with a 48-hour remediation deadline for federal agencies — one of the shortest ever issued — and published joint guidance with Five Eyes partners (NSA, FBI, ACSC, NCSC, CCCS) (NSA Press Release). Cisco Talos published a detailed threat intelligence report attributing the three-year exploitation campaign to UAT-8616, describing it as a sophisticated, persistent threat actor targeting critical infrastructure (Cisco Talos). Security researchers at Rapid7, Tenable, Sophos, and Horizon3.ai published technical analyses and detection guidance. The revelation that the vulnerability had been exploited since at least 2023 without detection generated significant concern in the security community, with coverage from BleepingComputer, Dark Reading, The Register, CyberScoop, and SecurityWeek highlighting the severity and the broader pattern of Cisco SD-WAN vulnerabilities being exploited in 2026 (BleepingComputer, Tenable Blog).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20224HIGH8.6
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20245HIGH7.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 04, 2026
CVE-2026-20262MEDIUM6.5
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 15, 2026
CVE-2026-20210MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20209MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management