CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild

2026-03-04T23:30:22Z0bc4b3b1675c33ee8d1b2757b6c9f35759fad572b9827c10b1c309e113e40eda
CVE-2026-20127CVSS:10.0Cisco Catalyst SD-WANUAT-8616authentication bypassexploited in the wildno workaroundpatch availableremote unauthenticatedsecurity advisoryvManagevSmartzero-day

What happened

Tenable reports a critical (CVSSv3 10.0) authentication-bypass zero-day, CVE-2026-20127, affecting Cisco Catalyst SD-WAN Controller (vSmart) and Manager (vManage). The flaw allows remote, unauthenticated attackers to send crafted requests and gain high-privilege access; active exploitation in the wild by a tracked actor (UAT-8616) has been observed. Cisco has released patches and multiple government advisories and threat-hunting guides have been issued; no mitigations/workarounds are currently available.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
0bc4b3b1675c33ee8d1b2757b6c9f35759fad572b9827c10b1c309e113e40eda
Enrichment time
2026-03-04T23:30:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild · Baitaphish