Vulnerabilities & Exploits · Zero-Day Exploit

Cisco SD‑WAN Zero‑Day Exploited by Nation‑State Since 2023

An unauthenticated auth‑bypass zero‑day (CVE‑2026‑20127) in Cisco Catalyst SD‑WAN Controller and Manager has been actively exploited by nation‑state actor UAT‑8616 since 2023.

1 source · Mar 9

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-03

Every edition of this story: Cisco SD‑WAN Zero‑Day Exploited by Nation‑State Since 2023

More from today