INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco SD-WAN Vulnerability Exploitation

| 2026-02-26 11:34 CRITICAL HIGH
Executive Summary AI-generated
The situation is dire. A critical vulnerability in Cisco Catalyst SD-WAN, identified as CVE-2026-20127, has been exploited in active cyberattacks zero-day that compromise controllers, insert devices into the network and escalate privileges to root access. The vulnerability affects both on-premise and cloud-based implementations of these products. The exploitation was likely achieved by degrading firmware to an earlier vulnerable version, exploiting CVE-2022-20775, and restoring it afterwards. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to inventory all Cisco SD-WAN systems, collect forensic artifacts, ensure external log storage is in place for logs, apply security updates, and analyze possible compromises related to CVE-2026-20127 and CVE-2022-20775. The presence of malicious entries in /var/log/auth.log indicates the vulnerability has been exploited. This situation poses a significant threat to organizations relying on Cisco SD-WAN products due to its critical nature and potential for widespread exploitation.
Technical Mitigations AI-generated
* Implement secure autenticación: Ensure that the peering mechanism is properly secured by implementing a strong authentication protocol, such as mutual TLS or IPsec, and regularly update the system to prevent exploitation of known vulnerabilities. * Keep software up-to-date: Regularly apply security patches and updates for Cisco Catalyst SD-WAN controllers to ensure you have the latest fixes for CVE-2026-20127 and CVE-2022-20775. This will help prevent exploitation by attackers who may exploit known vulnerabilities in older versions of the software. * Monitor logs and network traffic: Continuously monitor system logs, network traffic, and other relevant data streams to detect any suspicious activity that could indicate a potential attack on your Cisco SD-WAN infrastructure. * Implement access controls and segregation of duties (SoD): Ensure that users with elevated privileges have only necessary access to the system and can be separated from each other to prevent lateral movement in case of an incident. This includes implementing fine-grained access control, limiting user roles, and enforcing strict separation of duties between administrators. * Use a secure configuration management tool: Utilize a configuration management tool that supports secure configuration management practices, such as Ansible or Puppet, which can help ensure that your Cisco SD-WAN infrastructure is properly configured with the latest security patches and updates.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-20775CVE-2022-20775 CVE-2026-20127CVE-2026-20127
Target & Sectors
LA
technologytechnology
Incident Timeline
February 25, 2026
Threat actors exploited vulnerabilities affecting Cisco software-defined wide-area network (SD-WAN) systems.
source_region United Kingdom
vulnerability CVE-2026-20127
vulnerability CVE-2022-20775
attribution National Cyber Security Centre
attribution SD-WAN
2026-02-26
Un actor malicioso explotó una vulnerabilidad crítica en Cisco Catalyst SD-WAN, lo que permitió a un atacante comprometer controladores y insertar dispositivos maliciosos en la red.
organisation Cisco SD-WAN
organisation CVE-2022
organisation vSmart
organisation Initial Peering Event Analysis
organisation Cisco Catalyst SD-WAN
organisation CVSS
organisation CVE-2026
organisation SD-WAN Cloud
organisation Los socios de inteligencia de la compañía
organisation el actor
organisation Las degradaciones de software
organisation SD-WAN
organisation Additional Investigative Guidance
organisation Counter Threat Unit
organisation SophosLabs
organisation IPS
organisation the Cisco Catalyst SD-WAN
infrastructure Windows
organisation Controller
organisation Critical Infrastructure
organisation CI
organisation TAC
organisation IP
organisation Un
organisation el SD-WAN
organisation Validate
organisation SSH
organisation sospechosa de cuentas
organisation byte
organisation Snort
organisation Estados Unidos
organisation el riesgo
organisation Australian Cyber Security Centre
organisation del Australian Signals Directorate
organisation el mecanismo de peering
organisation defectuoso de autenticación de peering
organisation el sistema de autenticación
organisation el controlador SD-WAN
organisation el impacto es
organisation Escalada
organisation al conocerse que los ataques
organisation desde el punto de vista
organisation el atacante consigue privilegios root mientras
organisation Indicadores de
organisation SOC
organisation los registros de cualquier
organisation Cisco TAC
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product