Vulnerabilities & Exploits · Zero-Day Exploit

Cisco SD‑WAN Zero‑Day Exploited by Nation‑State Since 2023

UAT‑8616 has exploited an unauthenticated auth‑bypass zero‑day in Cisco Catalyst SD‑WAN Controller and Manager.

1 source · Mar 9

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-07

Every edition of this story: Cisco SD‑WAN Zero‑Day Exploited by Nation‑State Since 2023

More from today