CVE-2026-20127 - Vulnerability Analysis
CriticalCVSS: 10.0Last Updated: February 26, 2026
Cisco Catalyst SD-WAN Controller & Manager - Authentication Bypass
Overview
Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass caused by improper peering authentication, letting unauthenticated remote attackers obtain administrative privileges, exploit requires sending crafted requests.
Severity & Score
Impact
Unauthenticated attackers can gain administrative access and manipulate network configurations, risking full control over the SD-WAN fabric.
Mitigation
Update to the latest available version that fixes the peering authentication mechanism.
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20127
- https://blog.talosintelligence.com/uat-8616-sd-wan/
- https://media.defense.gov/2026/Feb/25/2003880301/-1/-1/0/CSA_Exploitation_of_SD-WAN_Appliances.PDF
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
Social Media Activity(2 posts)
This week's release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/
View original postThis week's release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/
View original postGitHub Repositories(6 repos)
- https://github.com/sfewer-r7/CVE-2026-20127
- https://github.com/abrahamsurf/sdwan-scanner-CVE-2026-20127
- https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE
- https://github.com/yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE
- https://github.com/randeepajayasekara/CVE-2026-20127
- https://github.com/BugFor-Pings/CVE-2026-20127_EXP
Related Resources
Details
- CVE ID
- CVE-2026-20127
- Severity
- Critical
- CVSS Score
- 10.0
- Type
- broken_authentication
- Status
- confirmed
- EPSS
- 3965.9%
- Social Posts
- 2
CWE
- CWE-287
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H