Critical Cisco SD-WAN zero-day is under active exploitation
Cisco has issued an advisory and emergency patches for a critical zero-day vulnerability in its Catalyst SD-WAN Controller and SD-WAN Manager platforms that is already being exploited. The flaw, tracked as CVE-2026-20127 with a CVSS score of 10.0, allows an unauthenticated remote attacker to bypass authentication and gain administrative access. Successful exploitation can enable manipulation of SD-WAN configuration fabrics and the introduction of rogue peers. CISA and partners across the Five Eyes alliance have urged immediate patching and added the vulnerability to the Known Exploited Vulnerabilities catalogue. The guidance is to apply patched releases without delay, restrict access to management interfaces and hunt for signs of compromise, particularly on internet-exposed controllers.
What this means for your organisation
Anyone with administrative access to SD-WAN management controls how traffic flows between sites. At that point this is not about one system but about the whole network and everything passing through it. The flaw is already being exploited, so the window for scheduled maintenance is gone. Organisations whose SD-WAN is run by a supplier need to know who actually applies the patch and when, rather than assuming it has been handled.
Berigo recommends
- Install Cisco's fixed releases now, and treat this as an incident rather than routine maintenance.
- Take management interfaces off the internet and place them behind a controlled access layer.
- Run an active hunt for compromise: new accounts, changed configuration and unknown peers in the fabric.
- Require written confirmation from your managed service provider on what was patched, when, and what they checked.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch