LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20127 to its Known Exploited Vulnerabilities catalog on Feb 25, 2026, with a federal patch deadline of Feb 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated…

This vulnerability is an authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. An unauthenticated remote attacker can exploit a flaw in the peering authentication mechanism to obtain administrative access and manipulate SD-WAN fabric configuration through NETCONF. The issue matters because successful exploitation grants control over network routing and policy without valid credentials, affecting organizations that rely on these components for wide-area traffic management.

How it works

The weakness is categorized as CWE-287, improper authentication. The peering authentication mechanism in the affected systems does not enforce checks correctly.

Exploit details beyond the summary must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Cisco Catalyst SD-WAN Controller (formerly vSmart) and Manager (formerly vManage) run in enterprise SD-WAN deployments that centralize control-plane functions. Inventory all instances of these components in your environment, including any cloud-hosted deployments.

How to remediate

Apply the vendor update referenced in the advisory as the primary fix. After patching, review and enforce strict access controls on management interfaces and NETCONF.

If you can't patch immediately

Adhere to CISA Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices. Apply network segmentation to limit reachability of Controller and Manager instances from untrusted networks.

If your data may have been exposed

Actively exploited authentication bypass vulnerabilities have led to unauthorized access and subsequent breaches. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Controller and Manager
WeaknessCWE-287
Added to CISA KEVFeb 25, 2026
Federal patch deadlineFeb 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities