Critical Cisco SD-WAN 0-Day Vulnerability Exploited Since 2023 to Gain Root Access
Cisco has identified a critical zero-day vulnerability in its Catalyst SD-WAN products . This flaw, tracked as CVE-2026-20127, has been exploited since 2023 to bypass authentication and achieve root access.
Cisco has identified a critical zero-day vulnerability in its Catalyst SD-WAN products . This flaw, tracked as CVE-2026-20127, has been exploited since 2023 to bypass authentication and achieve root access.
The vulnerability affects core networking components, necessitating urgent patching due to active attacks. CVE-2026-20127 is linked to a flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage).
An unauthenticated remote attacker can exploit this flaw by sending crafted requests to bypass checks, allowing login as a high-privileged, non-root internal user account. This access enables NETCONF manipulation, potentially altering the entire SD-WAN fabric's network configuration, including adding rogue peers or altering routing.
The vulnerability has a CVSS v3.1 base score of 10.0 (Critical), with an attack vector through the network, low complexity, no privileges required, and no user interaction needed.
This issue affects both on-premises deployments and Cisco-hosted SD-WAN Cloud environments, including standard, managed, and FedRAMP configurations. Cisco released patches on Thu, Feb 25, 2026, and confirmed no workarounds are available.
Active exploitation began at least in 2023, as revealed by Cisco Talos, tracking the campaign as UAT-8616. This effort is linked to post-compromise persistence in high-value targets such as critical infrastructure. Attackers have added malicious rogue peers to configurations, enabling sustained network access.
Cisco has identified a critical zero-day vulnerability in its Catalyst SD-WAN products .
Following bypass, actors reportedly downgraded software versions to exploit CVE-2022-20775, a path-traversal flaw, for root escalation, before restoring the original versions to avoid detection. This indicates sophisticated tactics targeting network edge devices for footholds. Reports from intelligence partners confirm the compromise of internet-exposed management/control planes.
Cisco Talos attributes these attacks to UAT-8616, assessed as a highly sophisticated actor with high confidence, focusing on SD-WAN for persistent access in critical sectors. No public indicators of compromise (IOCs) are detailed, but guides from partners emphasize checking peer configurations and version histories.
Product Affected Versions Fixed Versions
SD-WAN Controller (vSmart) 20.3.1 – 20.14.3, 20.15.1 20.14.4, 20.15.2
SD-WAN Manager (vManage) 20.3.1 – 20.14.3, 20.15.1 20.14.4, 20.15.2
Verification involves inventorying exposed ports and auditing NETCONF logs for anomalies. Temporary mitigations include restricting management plane access and monitoring for unauthorized peers.
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20127 and CVE-2022-20775 to its Known Exploited Vulnerabilities Catalog on Thu, Feb 25, 2026. Emergency Directive 26-03 mandates Federal Civilian Executive Branch (FCEB) agencies to inventory SD-WAN systems, patch within 21 days, and hunt for compromise indicators. The Australian Cyber Security Centre and Canadian Cyber Centre issued similar alerts, noting real-world rogue peer additions.
Immediately apply Cisco patches as per the advisory. Inventory all SD-WAN deployments, focusing on internet-facing controllers. Scan for rogue peers via CLI: show sdwan omp peers detail and review NETCONF sessions. Enable logging for authentication failures and version changes; reset compromised configurations if detected. Contact Cisco Technical Assistance Center (TAC) for support and follow Talos hunt guidance.
Organizations in critical infrastructure should prioritize checks, as UAT-8616 aims for enduring persistence. Broader adoption of zero-trust for edge devices is recommended to counter such trends.
Based on reporting by Cyber Security News.
