Cisco SD-WAN auth flaw fuels years-long zero-day campaigns, urgent patch urged

1 min read
Source: BleepingComputer
Cisco SD-WAN auth flaw fuels years-long zero-day campaigns, urgent patch urged
Photo: BleepingComputer
TL;DR Summary

Cisco warns of a critical authentication-bypass vulnerability in Catalyst SD-WAN (CVE-2026-20127) that attackers actively exploited since 2023 to log in as a high-privilege user, insert rogue peers, and potentially gain root access. Government advisories (CISA and UK NCSC) issued urgent directives; Cisco released updates but says no workaround fully mitigates the issue. Organizations should harden exposed interfaces, review logs for anomalous peering, and patch promptly.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

6 min

vs 6 min read

Condensed

95%

1,19965 words

Want the full story? Read the original article

Read on BleepingComputer