INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco SD-WAN Flaw Exploitation Under Attack

| 2026-03-12 12:45 CRITICAL HIGH
Executive Summary AI-generated
The newly issued emergency directive from the US Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting vulnerabilities in Cisco Catalyst SD-WAN infrastructure used across US federal networks. The affected technology is widely used to manage distributed enterprise networks, making successful exploitation a significant threat to key communications infrastructure. CISA director Bobby Kuzma stated that the agency believes these vulnerabilities have been exploited by threat actors to compromise government systems and networks, prompting federal agencies to comply with emergency directives issued by CISA when significant cybersecurity threats are identified. The warning centers on a flaw tracked as CVE-2026-20127, described as a critical authentication bypass vulnerability with a CVSS severity score of 10.
Technical Mitigations AI-generated
* Implement a patch management system to ensure timely application of security updates and minimize downtime. * Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses in SD-WAN infrastructure. * Configure devices with external logging capabilities to collect and store logs, making it easier to detect and respond to potential compromises. * Establish a centralized incident response plan that includes procedures for collecting artifact evidence, submitting reports to CISA, and investigating potential threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20122CVE-2026-20122 CVE-2026-20128CVE-2026-20128 CVE-2026-20127CVE-2026-20127 CVE-2022-20775CVE-2022-20775
Target & Sectors
FIVE_EYES FIVE_EYES governmentgovernment technologytechnology
Incident Timeline
February 25, 2026
CISA issued an Emergency Directive requiring Federal agencies to inventory Cisco SD-WAN systems, collect forensic artifacts and logs, apply security updates, investigate potential compromises tied to the CVE-2026-20127 vulnerability.
vulnerability CVE-2026-20127
vulnerability CVE-2022-20775
attribution CVE-2022
general_metric 20775 threat actor
attribution Federal Civilian Executive Branch
attribution Cisco SD-WAN
general_metric 26 Emergency Directive
2026-02-25
Threat actors used Cisco's SD-WAN peering authentication mechanism to target the company.
February 25
Cisco released security patches on February 25 for five Catalyst SD-WAN vulnerabilities.
Feb 26, 2026
Threat actors used a known vulnerability in Cisco's SD-WAN software to gain unauthorized access and compromise the company's network.
February 26, 2026
Threat actors used a vulnerability in Cisco's SD-WAN software to gain unauthorized access.
February 27, 2026
Threat actors exploited Cisco SD-WAN vulnerabilities in General Document Context Version 20.9 to target the involved entities by February 27, 2026.
attribution CISA
infrastructure 20.9
infrastructure 20.9.8
observable 20.9.8.2
general_metric 20.9 20.9.8.2
March 5, 2026
Threat actors used Cisco's software to target vulnerable products.
March 5
Threat actors used a previously unknown vulnerability in Cisco's SD-WAN software to exploit CVE-2026-20128 and CVE-2026-20122 on March 5.
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
2026-02-10T22:51:36+
Threat actors used a known vulnerability in Cisco SD-WAN to exploit the affected system by targeting users with access to sensitive data.
observable auth.log
organisation IP
2026-03-12
Threat actors used a newly abused flaw in Cisco Catalyst SD-WAN Manager to target systems.
organisation NCSC
organisation CVE-2026-20127
organisation Cisco Catalyst SD-WAN Controller
organisation Cisco Catalyst SD-WAN
organisation SD-WAN Cloud
organisation Cisco CVE-2026-20127
organisation Cisco SD-WAN Zero-Day CVE-2026-20127
organisation Admin Access
organisation CVE-2022-20775
organisation Catalyst SD-WAN Controller
organisation CVSS
organisation Admins
infrastructure 7.8
organisation CVE-2022
organisation CLI
organisation Cisco SD-WAN
organisation Vulnerability / Network Security
organisation Catalyst SD-WAN
organisation IP
organisation the Cisco Catalyst SD-WAN
organisation UI
organisation the Australian Signals Directorate's
organisation Australian Cyber Security Centre
organisation ASD
organisation Cisco Hosted SD-WAN Cloud - Cisco Managed
organisation Cisco Hosted SD-WAN Cloud - FedRAMP Environment
organisation Cisco
organisation Cisco SD-WANs
organisation NETCONF
organisation SD-WAN
organisation Data Collection
organisation DCA
organisation BleepingComputer
organisation KEY
organisation Modern
organisation Tines
infrastructure 20.91
organisation Cisco Catalyst SD-WAN - Prior
infrastructure 20.9.8
infrastructure 20.12.6
infrastructure 20.12.5
infrastructure 20.15.4
infrastructure 20.18.2
infrastructure 20.111
infrastructure 20.131
infrastructure 20.141
infrastructure 20.15
infrastructure 20.161
infrastructure 20.18
organisation SD-WAN vManage
organisation Cisco Hosted SD-WAN Cloud
organisation the Australian Signals Directorate’s
organisation SSH
organisation Used Network Configuration Protocol
organisation Critical Infrastructure
organisation CI
infrastructure 20.9.1
organisation SecurityAffairs
organisation National Cyber Security Centre
March 23, 2026
Threat actors exploited Cisco SD-WAN vulnerabilities to compromise government systems and networks.
organisation Cisco SD-WAN
organisation Kuzma
organisation Shutterstock.com
March 2026
Threat actors have already exploited the vulnerabilities described in CVE-2026-20128 and CVE-2026-20122.
vulnerability CVE-2026-20128
vulnerability CVE-2026-20122
organisation CVE-2026
March 26, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to affected organizations due to newly discovered vulnerabilities in Cisco's SD-WAN products.
Tactical Metrics
Metrics
infrastructure
​7.8
Software Version
Metrics
infrastructure
​20.91
Software Version
Metrics
infrastructure
​20.9
Software Version
Metrics
infrastructure
​20.9.8
Software Version
Metrics
infrastructure
​20.111
Software Version
Metrics
infrastructure
​20.12.6
Software Version
Metrics
infrastructure
​20.12.5
Software Version
Metrics
infrastructure
​20.131
Software Version
Metrics
infrastructure
​20.15.4
Software Version
Metrics
infrastructure
​20.141
Software Version
Metrics
infrastructure
​20.15
Software Version
Metrics
infrastructure
​20.161
Software Version
Metrics
infrastructure
​20.18.2
Software Version
Metrics
infrastructure
​20.18
Software Version
Metrics
infrastructure
​20.9.1
Software Version
Intelligence Sources
The Register - Cybercrime 2026-03-06
Infosecurity-Magazine 2026-03-12