Cisco warns of a critical SD-WAN bug that was actively exploited in zero-day attacks since 2023; CISA and its international partners issue emergency directives
Cisco’s disclosure places Catalyst SD-WAN alongside a recurring pattern of exploited network-device flaws, including an earlier IOS XE zero-day exploited in the wild. The report’s claim that exploitation dates to 2023 makes remediation an incident-response issue, not solely a preventive patching task.
The emergency action follows CISA’s prior directive on exploited Cisco firewall flaws, reinforcing that actively exploited edge and network infrastructure can quickly move from a vendor advisory into government-led operational requirements.
First-order effects
Cisco Catalyst SD-WAN operators must apply Cisco’s remediation and investigate systems for evidence of prior unauthorized access, given the reported long-running exploitation of the authentication bypass.
CISA’s emergency directive, echoed by international partners, raises the immediate compliance and response burden for affected public-sector organizations and their network-security teams.
Second-order effects
Organizations that depend on managed network providers will seek confirmation that exposed SD-WAN deployments have been remediated and assessed, extending the response beyond teams that directly administer the appliances.
The case increases pressure on network-equipment vendors and security teams to prioritize internet-facing management and authentication controls, since exploited flaws can trigger rapid government intervention.
Third-order effects
If emergency directives continue to follow exploited network-device vulnerabilities, vulnerability management will become more tightly coupled to operational mandates and accelerated remediation timelines for critical infrastructure.
The pattern favors security programs that can rapidly inventory network assets, validate patches, and investigate historical exposure; organizations without those capabilities may face greater disruption when directives arrive.
The trend: Actively exploited flaws in widely deployed network infrastructure are increasingly turning vendor patch cycles into coordinated, policy-backed incident-response events.
🚨 Just Released: Emergency Directive 26-03 focuses on mitigating vulnerabilities in Cisco SD-WAN systems. We urge all orgs to review and implement the recommended actions immediately to protect your network. 👉 https://go.dhs.gov/iHq [video]
🚨 Malicious cyber actors are targeting and compromising Cisco SD-WAN systems deployed by organizations worldwide. These actors have exploited a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using [image…
🚨 Cyber threat actors are exploiting multiple Cisco vulnerabilities, including CVE-2026-20127 and CVE-2022-20775, to ultimately establish long-term persistence in SD-WAN systems across multinational organizations. Review our Alert & act immediately. 👉 https://go.dhs.gov/iHw [vide…
#CyberAlert Malicious cyber threat actors are targeting #Cisco SD-WAN networks used by organizations around the world. Read our alert: https://www.cyber.gc.ca/... [image]
New: @CISAgov orders agencies to quickly patch serious Cisco SD-WAN device vulnerabilities, including two that the agency says are being exploited in ways that imminently threaten government networks: https://www.cybersecuritydive.com/ ... [image]
🚨 watchTowr is rapidly reacting to CVE-2026-20127, a critical auth bypass in Cisco's Catalyst SD-WAN Controller with active in-the-wild exploitation reported. Patch urgently. Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr [i…
The NCSC, alongside international cyber agency partners, has put out an alert warning that “malicious cyber threat actors are targeting Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) used by organisations globally.” — www.ncsc.gov.uk/news/exploit...
The signals intelligence groups of all the Five Eyes nations have issued an emergency directive regarding Cisco SD-WAN Systems in response to what they say is a significant cyber threat. — www.cisa.gov/news-events/...
Exploitation of Cisco Catalyst SD-WAN — Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN, and full updating and hardening. — www.ncsc.gov.uk/news/exploit...