Back Computing Patch critical Cisco zero day now, urge security agencies
Cisco has disclosed a critical zero day vulnerability in its Cisco Catalyst SD-WAN that is being actively exploited in the wild.
The main flaw is CVE-2026-20127, an authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller and Catalyst SD-WAN Manager in both on-premises and cloud setups.
CVE‑2026‑20127 , which carries a maximum severity score of 10.0, allows an unauthenticated remote user to bypass authentication and gain root access through privilege escalation. The attacker can then alter the SD‑WAN control‑plane configuration and insert rogue peers into the system, allowing long‑term access and lateral movement.
SD‑WAN controllers sit at the heart of enterprise and government networks, making them a prime target for attackers seeking to spy on or disrupt operations.
Cisco Talos, the company’s cyber arm, says the vulnerability has been exploited since 2023 , adding that it is currently monitoring a “highly sophisticated” threat group codenamed UAT-8616. It does not provide further details of the threat actor.
With the vulnerability under active attack, security agencies from the UK, US, Canada, Australia and New Zealand have put out a Hunt Guide to support network defenders to conduct detection and threat hunting activities, along with guidance on mitigating the threat.
The UK National Cyber Security Centre (NCSC) advises all organisations using Cisco Catalyst SD-WAN to ensure management interfaces are not exposed to the internet, follow the steps in the Hunt Guide, and report any anomalies to the authorities. Instances should be upgraded to the latest version, and admins should apply the Cisco Catalyst SD-WAN Hardening Guide .
In the US, the Cybersecurity and Information Security Agency (CISA) has described the vulnerability as an imminent threat to federal networks, mandating that affected systems be patched by 27 th February.
Moshe Hassan, VP of research and innovation at security vendor Upwind commented that time is of the essence when it comes to patching vulnerabilities in core systems.
“Exploitation of network appliances is often a preferred route for sophisticated threat actors because it can provide durable, high-impact access with fewer opportunities for endpoint controls to intervene,” he said. “Once details of a vulnerability become broadly known, exploitation often widens beyond the initial actor set. That’s why the window right after disclosure is critical: reduce exposure immediately, patch fast, and actively monitor for indicators of compromise rather than relying on prevention alone.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
