Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposurerapid-weaponizationproof-of-concept-release

Active Exploitation of Cisco SD-WAN Vulnerabilities Beyond CVE-2026-20127

Updated 1mo agoFirst seen Mar 19, 20267 sources

Researchers warned that defenders may be underestimating the risk from Cisco SD-WAN flaws beyond the widely publicized zero-day CVE-2026-20127, particularly CVE-2026-20133, a high-severity issue tied to inadequate file system access restrictions. VulnCheck reported that public attention and detection efforts have focused too narrowly on CVE-2026-20127, even though proof-of-concept activity attributed to that bug appears to affect other vulnerabilities, including CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. Defused researchers said their telemetry supports that assessment, indicating that CVE-2026-20127 is generating heavy automated noise while activity involving CVE-2026-20133, if present, is likely quieter and easier to miss.

Broader reporting indicates the SD-WAN issue is part of a larger pattern of active exploitation across Cisco edge infrastructure, with multiple recently disclosed SD-WAN and firewall vulnerabilities already exploited in the wild. CyberScoop reported that five of nine Cisco flaws disclosed across firewalls and SD-WAN systems in recent weeks have seen exploitation, including two SD-WAN zero-days abused for years before discovery and three additional SD-WAN defects later confirmed under attack. The reporting also noted exploitation of a maximum-severity Cisco firewall management flaw by Interlock ransomware, underscoring that attackers are targeting management-plane and control-plane weaknesses in network-edge products that often serve as enterprise trust anchors.

Share:
Active Exploitation of Cisco SD-WAN Vulnerabilities Beyond CVE-2026-20127
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Apr 21, 20261mo ago

CISA adds Cisco SD-WAN flaw CVE-2026-20133 to KEV catalog

CISA added Cisco Catalyst SD-WAN Manager vulnerability CVE-2026-20133 to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency ordered Federal Civilian Executive Branch agencies to secure affected systems by 2026-04-24 and follow Emergency Directive 26-03 and Cisco hardening guidance.

CISA flags new SD-WAN flaw as actively exploited in attacks
Apr 20, 20261mo ago

CISA adds CVE-2026-20128 and CVE-2026-20122 to KEV catalog

CISA added Cisco Catalyst SD-WAN Manager flaws CVE-2026-20128 and CVE-2026-20122 to its Known Exploited Vulnerabilities catalog after Cisco confirmed active exploitation. Federal agencies were given a remediation deadline in late April 2026, expanding U.S. government response beyond CVE-2026-20133 alone.

CISA flags 3 exploited Cisco vulnerabilities for patching - SDxCentral
Mar 18, 20262mo ago

Researchers warn CVE-2026-20133 may be the more urgent SD-WAN threat

VulnCheck assessed that the high-severity Cisco Catalyst SD-WAN flaw CVE-2026-20133 may pose a greater immediate risk than the more publicized zero-day CVE-2026-20127. Defused researchers also said vulnerable SD-WAN devices were being targeted through multiple avenues and that CVE-2026-20133 exploitation may be quieter and easier to miss.

Researchers identify misattributed PoC affecting other Cisco flaws

VulnCheck reported that a proof-of-concept published by ZeroZenX Labs for CVE-2026-20127 did not actually target that zero-day, but instead affected CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. The finding suggested defenders may be misjudging which SD-WAN vulnerabilities are most urgent.

Cisco discloses multiple SD-WAN and firewall vulnerabilities

Cisco recently disclosed nine vulnerabilities affecting SD-WAN and firewall management products, with five later confirmed as exploited in the wild. The disclosures included the zero-day CVE-2026-20127 and other SD-WAN flaws such as CVE-2026-20133.

Feb 28, 20263mo ago

Cisco patches three Catalyst SD-WAN Manager flaws

Cisco released fixes in late February 2026 for CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 affecting Catalyst SD-WAN Manager. The vulnerabilities were later cited by CISA as actively exploited or included in its Known Exploited Vulnerabilities catalog.

More Cisco SD-WAN bugs battered in attacks • The Register
Feb 25, 20263mo ago

CISA orders federal agencies to assess and patch Cisco SD-WAN Manager

CISA issued an emergency directive requiring federal executive branch agencies to assess and patch Cisco SD-WAN Manager systems after concerns about active exploitation. The directive elevated the urgency of the Cisco SD-WAN vulnerability situation for U.S. government networks.

Security teams might be overlooking wider threat to Cisco SD-WAN | Cybersecurity Dive
Jan 26, 20264mo ago

Attackers begin exploiting Cisco firewall management flaw

Amazon Threat Intelligence said the Interlock ransomware group started exploiting a maximum-severity Cisco firewall management vulnerability before it was publicly disclosed. The exploitation reportedly began on January 26 and targeted firewall management infrastructure.

Mar 18, 20233y ago

Cisco SD-WAN zero-days were exploited for years before disclosure

Two Cisco SD-WAN zero-day vulnerabilities were reportedly exploited in the wild for at least three years before Cisco disclosed them. This indicates long-running attacker access to SD-WAN management or control-plane systems prior to public awareness.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Active Exploitation of Cisco SD-WAN Vulnerabilities Beyond CVE-2026-20127 | Mallory