CVE-2026-20127: Improper Authentication in Cisco Cisco Catalyst SD-WAN Manager
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.
Indicators of Compromise
- cve: CVE-2026-20127
- cve: CVE-2026-20182
- cve: CVE-2026-20245
- hash: b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b
CVE-2026-20127: Improper Authentication in Cisco Cisco Catalyst SD-WAN Manager
Description
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.
CVSS v3.1
Score 10.0critical
Affected software
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2025-10-08T11:59:15.379Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Indicators of Compromise
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-20127 | — | |
cveCVE-2026-20182 | — | |
cveCVE-2026-20245 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashb82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b | — |
Threat ID: 699f6dd9b7ef31ef0b58f88d
Added to database: 02/25/2026, 21:47:05 UTC
Last enriched: 03/05/2026, 11:32:00 UTC
Last updated: 07/31/2026, 19:23:38 UTC
Views: 189
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.