Vulnerabilities & Exploits · APT / Espionage

Cisco Control Plane Under Active Attack

Patching the edge box is not the whole fix here. The break is in the management and peering layers that govern routing, segmentation, and admin trust, so one compromise can give an attacker control over the network control plane instead of just a single appliance.

Cisco says it has sped up and reprioritized disclosures as active abuse continues across Cisco Catalyst SD-WAN and Cisco Secure Firewall products. The wave now reaches government and critical infrastructure, and Cisco Talos has tied different flaws in the SD-WAN stack to access, web shells, and command execution on the device.

That matters because these systems are trust anchors. If the control plane falls, the attacker can inherit policy and visibility across a much larger slice of the environment, and fixing the vulnerable version does not by itself undo the trust already lost.

10 sources · Jul 8

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

CVE-2026-20182

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: may 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026.

CISA federal remediation date May 17 · date passed

CVE-2026-20133

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: a vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive… EPSS 32% (98th percentile).

CISA federal remediation date Apr 23 · date passed

CVE-2026-20245

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN… EPSS 25% (98th percentile).

CISA federal remediation date Jun 23 · date passed

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-06-24

Every edition of this story: Cisco Control Plane Under Active Attack

More from today