CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems – 2/25/26

CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.

Click here to visit a link to the CISA alert.