INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco SD-WAN Flaw Exploited Months Before Disclosure

| 2026-06-25 14:15 CRITICAL HIGH
Executive Summary AI-generated
The recent discovery of a severe vulnerability in Cisco Catalyst SD-WAN Manager has exposed the company's edge devices to unauthorized access, potentially leading to catastrophic consequences. This critical flaw was disclosed by Cisco on June 4 after it observed limited cases where exploitation resulted in configuration changes pushed to affected devices. The researchers at Mandiant, part of Google Cloud, identified a threat actor targeting SD-WAN infrastructure as early as late 2025 and noted further unauthorized peering connections were made in January 2026. This malicious activity could be linked to the exploitation of CVE-2026-20127 or CVE-2026-20182, which are also critical vulnerabilities recently disclosed by Cisco affecting the peering authentication mechanism for SD-WAN controllers.
Technical Mitigations AI-generated
* Implement robust input validation and sanitization mechanisms to prevent unauthorized data injection, such as CSV uploads. * Regularly update and patch operating systems, network devices, and software applications to ensure timely fixes for known vulnerabilities like CVE-2026-20245. * Use secure protocols (e.g., SSH) for remote access and authentication, and limit the privileges of users with elevated access levels. * Monitor network traffic and logs for suspicious activity, and implement intrusion detection systems (IDS) or intrusion prevention systems (IPS) to detect potential threats in real-time.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20182CVE-2026-20182 CVE-2026-20127CVE-2026-20127 CVE-2026-20245CVE-2026-20245 CVE-2022-20775CVE-2022-20775
Target & Sectors
NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES technologytechnology governmentgovernment
Incident Timeline
‎September 2022
Threat actors exploited CVE-2026-20127 vulnerability in Cisco products before its official disclosure to gain admin rights and access NETCONF.
vulnerability CVE-2026-20127
organisation CVE-2022-20775
organisation NETCONF
general_metric 20775 CVE-2022
general_metric 7.8 CVE-2022
‎at least 2023
Threat actors exploited a previously unknown Cisco vulnerability, UAT-8616, at least as early as 2023.
‎between late 2025
Threat actors used a previously unknown vulnerability in Cisco's SD-WAN software to target the service provider between late 2025 and January 2026.
vulnerability CVE-2026-20245
organisation Mandiant
organisation SD-WAN
‎late 2025
Threat actors used rogue peering to gain initial access months before the Cisco vulnerability was publicly disclosed.
‎January 2026
Threat actors exploited CVE-2026-20127 to gain initial access via unauthorized peering connections.
vulnerability CVE-2026-20245
organisation Mandiant
organisation SD-WAN
organisation CSV
organisation SSH
‎March 2026
US agencies were warned to scrap end-of-support for Edge devices due to a known vulnerability exploited months before its official disclosure.
organisation CVE
‎June 4
Threat actors exploited the Cisco CVE-2026-20245 vulnerability months before its public disclosure.
vulnerability CVE-2026-20245
source_region United States
‎June 10
Threat actors exploited a previously undisclosed Cisco vulnerability, CVE-2026-20245, in the Catalyst SD-WAN Manager software approximately 30 days before its official release.
vulnerability CVE-2026-20245
organisation Catalyst SD-WAN
‎June 12
Threat actors exploited a Privilege Escalation vulnerability in Cisco systems for months before the company publicly disclosed it.
tactic Privilege Escalation
‎June 23
Threat actors exploited a previously undisclosed Cisco vulnerability months before its official disclosure.
organisation Federal Civilian Executive Branch
organisation FCEB
‎June 24
Threat actors used a previously undisclosed vulnerability in Cisco's SD-WAN software to target an infrastructure at a service provider.
organisation Mandiant
organisation SD-WAN
‎late 2025 to January 2026
Threat actors exploited a previously undisclosed Cisco vulnerability in late 2025 to January 2026.
‎the late 2025 to January 2026
Threat actors exploited a previously undisclosed Cisco vulnerability in the late 2025 to January 2026 timeframe.
‎2026/06/25
Threat actors exploited a severe vulnerability in Cisco products, including the SD-WAN Manager and Validator devices, at least two months before its disclosure.
organisation CLI
organisation Cisco Catalyst SD-WAN Controller
organisation SD-WAN vSmart
organisation Catalyst SD-WAN Controller
organisation Catalyst SD-WAN
organisation Initial Access Via Rogue
organisation the Australian Cyber Security Centre
organisation SD-WAN Controller
organisation Cisco Vulnerability Exploited
organisation Google
organisation Cisco Catalyst SD-WAN
organisation Cisco Catalyst SD-WAN Validator
organisation CTO
organisation Vulnerability Disclosure
organisation SD-WAN
organisation NCSC
organisation The Register
‎early 2026
Threat actors used a previously unknown vulnerability in Cisco's SD-WAN software to target an infrastructure at a service provider.
organisation Mandiant
organisation SD-WAN
Intelligence Sources
The Register - Cybercrime 2026-06-17
Infosecurity-Magazine 2026-06-25