Dossier
CVE-2026-20127
Coverage of CVE-2026-20127 in the Nexus archive.
Ciscoorganization2CVE-2026-20245topic2CVE-2026-20182topic2Mandiantorganization1Cisco Catalyst SD-WAN Managertopic1Landon Riceperson1Cybersecurity and Infrastructure Security Agencyorganization1Catalyst SD-WAN Managertopic1The Registerorganization1Cisco TACorganization1CVE-2026-20128topic1CVE-2026-20133topic1CVE-2026-20122topic1
- Cisco customers encounter another SD-WAN zero-day under attack
Cisco customers are facing another actively exploited zero-day vulnerability (CVE-2026-20245) in its SD-WAN management software, marking the seventh such exploit this year. The flaw allows authenticated attackers to execute commands as root, but Cisco warns no patch or workaround is currently available, and exploitation requires existing credentials or prior vulnerabilities.
- Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
Cisco's SD-WAN management software is under attack due to a high-severity zero-day vulnerability (CVE-2026-20245), which allows authenticated attackers to escalate privileges and execute commands. Cisco has not yet released a patch, and this is the sixth SD-WAN vulnerability exploited since the year began.