Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 88.2%top 0.25%

CVE-2026-20127: Improper Authentication in Cisco Cisco Catalyst SD-WAN Manager

0
Critical
Published: 06/25/2026 (06/25/2026, 15:21:09 UTC)
Source: CVE Database V5
Vendor/Project: Cisco
Product: Cisco Catalyst SD-WAN Manager

Description

In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

Affected versions
20.1.1219.2.118.4.418.4.520.1.1.120.1.119.3.019.2.219.2.09918.3.618.3.719.2.018.3.819.0.019.1.018.4.30218.4.30319.2.09719.2.09817.2.1018.3.6.119.0.1a18.2.018.4.318.4.117.2.818.3.3.118.4.018.3.117.2.617.2.918.3.417.2.518.3.1.118.3.518.4.0.118.3.317.2.717.2.418.3.019.2.318.4.501_ES20.3.120.1.219.2.92919.2.3120.3.219.2.3220.3.2_92520.3.2.120.3.2.1_92718.4.620.1.2_93720.4.120.3.2_92820.3.2_92920.4.1.0.120.3.2.1_93019.2.420.5.0.1.120.4.1.120.3.319.2.4.0.120.3.2_93720.3.3.120.5.120.1.320.3.3.0.420.3.3.1.220.3.3.1.120.4.1.220.3.3.0.220.4.1.1.520.4.1.0.0120.4.1.0.0220.3.3.1.720.3.3.1.520.5.1.0.120.3.3.1.1020.3.3.0.820.4.220.4.2.0.120.3.420.3.3.0.1419.2.4.0.819.2.4.0.920.3.4.0.120.3.2.0.520.6.120.5.1.0.220.3.3.0.1720.6.1.120.6.0.18.320.3.2.0.620.6.0.18.420.4.2.0.220.3.3.0.1620.3.4.0.520.6.1.0.120.3.4.0.620.6.220.7.1EFT220.3.4.0.920.3.4.0.1120.4.2.0.420.3.3.0.1820.7.120.6.2.120.3.4.120.5.1.120.4.2.120.4.2.1.120.3.4.1.120.3.81320.3.4.0.1920.4.2.2.120.5.1.220.3.4.220.3.81420.4.2.220.6.2.220.3.4.2.120.7.1.120.3.4.1.220.6.2.2.220.3.4.0.2020.6.2.2.320.4.2.2.220.3.520.6.2.0.420.4.2.2.320.3.4.0.2420.6.2.2.720.6.320.3.4.2.220.4.2.2.420.7.1.0.220.8.120.3.5.0.820.3.5.0.920.4.2.2.820.3.5.0.720.6.3.0.720.6.3.0.520.6.3.0.1020.6.3.0.220.7.220.9.1EFT220.6.3.0.1120.6.3.120.6.3.0.1420.6.420.9.120.6.3.0.1920.6.3.0.1820.3.620.9.1.120.6.3.0.2320.6.4.0.420.6.3.0.2520.6.520.6.3.0.2720.9.220.9.2.120.6.3.0.2920.6.3.0.3120.6.3.0.3220.10.120.6.3.0.3320.9.2.0.0120.9.1_LI_Images20.10.1_LI_Images20.9.2_LI_Images20.3.720.9.320.6.5.120.11.120.11.1_LI_Images20.6.3.1.120.9.3.0.220.6.5.1.220.9.3.0.320.4.2.320.6.3.220.6.4.120.6.3.0.3820.6.3.0.3920.3.5.120.3.4.320.9.3.120.3.3.220.6.5.220.3.7.120.10.1.120.6.5.2.120.3.4.0.2520.6.2.2.420.6.1.220.11.1.120.9.3.0.520.3.4.0.2620.6.5.1.320.6.3.0.4020.1.3.120.9.2.220.6.5.2.320.6.5.1.420.6.5.320.6.3.0.4120.9.3.0.720.6.5.1.520.9.3.0.420.6.4.0.1920.6.5.1.620.9.3.0.820.6.3.320.3.7.220.6.5.420.6.5.1.720.9.3.0.1220.6.4.220.6.5.520.9.3.220.11.1.220.6.3.420.10.1.220.6.5.1.920.9.3.0.1620.6.3.0.4520.6.5.1.1020.9.3.0.1720.6.5.2.420.6.4.0.2120.9.3.0.1820.6.3.0.4620.6.3.0.4720.9.2.320.9.3.2_LI_Images20.9.3.0.2120.9.3.0.2020.9.4_LI_Images20.9.420.6.5.1.1120.12.120.12.1_LI_Images20.6.5.1.1320.9.3.0.2320.6.5.2.820.9.4.120.9.4.1_LI_Images20.9.3.0.2520.9.3.0.2420.6.5.1.1420.3.820.6.620.9.3.0.2620.6.3.0.5120.9.3.0.2920.12.220.12.2_LI_Images20.6.6.0.120.13.1_LI_Images20.9.4.0.420.13.120.9.4.1.120.9.520.9.5_LI_Images20.12.3_LI_Images20.12.320.9.4.1.320.6.720.9.5.120.9.5.1_LI_Images20.9.4.1.620.14.120.14.1_LI_Images20.9.5.220.9.5.2.120.9.5.2_LI_Images20.12.3.120.12.420.15.1_LI_Images20.15.120.9.5.1.420.9.5.2.720.9.5.2.1320.9.620.9.6_LI_Images20.9.5.2.1420.6.820.12.4.0.0320.16.120.16.1_LI_Images20.12.4_LI_Images20.9.5.2.1620.12.4.0.420.12.40120.9.5.320.9.5.3_LI_Images20.12.4.1_LI_Images20.12.4.120.9.5.2.2120.9.6.0.320.12.4.0.620.15.2_LI_Images20.15.220.12.4_Monthly_ES520.12.520.12.5_LI_Images20.9.720.15.320.12.50120.12.5.1_LI_Images20.12.5.120.12.5.2_LI_Images20.12.5.220.15.3.120.15.4_LI_Images20.15.420.9.7.120.18.120.18.1_LI_Images20.12.6_LI_Images20.12.620.12.5.1.0120.9.820.9.8_LI_Images20.18.220.15.4.1_LI_Images20.15.4.120.18.2_LI_Images

Technical Details

Data Version
5.2
Assigner Short Name
cisco
Date Reserved
2025-10-08T11:59:15.379Z
Cvss Version
3.1
State
PUBLISHED

Indicators of Compromise

Cve

ValueDescriptionCopy
cveCVE-2026-20127
cveCVE-2026-20182
cveCVE-2026-20245

Hash

ValueDescriptionCopy
hashb82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b

Threat ID: 699f6dd9b7ef31ef0b58f88d

Added to database: 02/25/2026, 21:47:05 UTC

Last enriched: 03/05/2026, 11:32:00 UTC

Last updated: 07/31/2026, 19:23:38 UTC

Views: 189

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses