CyberzSOC

Publication detail
← Back to advisories & guidance

CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems ↗ source

February 25, 2026 CISA Alert
Co-sealed by: ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NSA

Summary

The purpose of this Alert is to provide resources for organizations with Cisco Software-Defined Wide-Area Networking (SD-WAN) systems, including Federal Civilian Executive Branch (FCEB) agencies, to address ongoing exploitation of multiple vulnerabilities. Notably, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20127 and CVE-2022-20775 to its Known Exploited Vulnerabilities (KEV) Catalog on Feb. 25, 2026. Additionally, CISA added CVE-2026-20133 on April 20, 2026 and CVE-2026-20182 to its KEV Catalog on May 14, 2026, respectively. As a result of the malicious cyber activity and vulnerabilities involving Cisco SD-WAN systems, CISA has outlined requirements for FCEB agencies in Emergency Directive (ED) 26-03 to inventory Cisco SD-WAN systems, update them, and assess compromise.

News Coverage

DateSourceArticle
2026-05-26 FortiGuard Labs Threat Signal Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127
2026-05-18 Check Point Research 18th May – Threat Intelligence Report CVE-2026-20182

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-20127 10.0 Critical Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypas…
CVE-2026-20182 10.0 Critical Cisco Catalyst SD-WAN Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass a…
CVE-2022-20775 7.8 High Cisco SD-WAN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper ac…
CVE-2026-20133 6.5 Medium Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.