Full Report
A rare joint alert from all five spy agencies means serious business The Five Eyes intelligence alliance is urgently warning defenders to patch two Cisco Catalyst SD-WAN vulnerabilities used in attacks.…
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Critical Flaws Used in Active Exploitation (Five Eyes Joint Alert)
## CVE Details
- CVE ID: CVE-2026-20127
- CVSS Score: 10.0 (Critical)
- CWE: Improper Authentication (Implied)
- CVE ID: CVE-2022-20775
- CVSS Score: 7.8 (High)
- CWE: Path Traversal (Implied)
## Affected Systems
- Products:
- Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
- Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
- Versions: Specific vulnerable versions are not listed, but immediate patching is urged for all relevant installations.
- Configurations: Affects devices utilizing the affected Controller and Manager components.
## Vulnerability Description
The alert covers two vulnerabilities, with **CVE-2026-20127** being the critical flaw allowing unauthorized access.
1. **CVE-2026-20127 (CVSS 10.0):** An improper authentication flaw affecting the Controller and Manager components. Successful exploitation grants administrative rights, allowing attackers to reconfigure the entire SD-WAN fabric via NETCONF access.
2. **CVE-2022-20775 (CVSS 7.8):** A path traversal vulnerability in the SD-WAN Command Line Interface (CLI) that allows for privilege escalation.
Attackers have reportedly chained these vulnerabilities: using CVE-2026-20127 to gain admin rights, followed by exploiting CVE-2022-20775 to downgrade the software version to achieve root access and maintain persistence.
## Exploitation
- Status: **Exploited in the wild** (since at least 2023, attributed to threat group UAT-8616).
- Complexity: Implied **Low/Medium** given the critical nature of the primary flaw and successful widespread attacks.
- Attack Vector: Network (Remote exploitation of management interfaces).
## Impact
The primary goal of the exploitation chain is establishing persistent access to high-value organizations.
- Confidentiality: High (Access to fabric data and configuration)
- Integrity: High (Ability to reconfigure the entire SD-WAN fabric)
- Availability: High (Ability to cause service disruption via root access/reconfiguration)
## Remediation
### Patches
- Upgrade to the **latest version** of Cisco Catalyst SD-WAN Controller and Manager software that remediates both vulnerabilities. (Specific version numbers are not listed in the summary text, vendor advisories must be consulted).
### Workarounds
- The Five Eyes advisory strongly recommends following the relevant **Hunt Guide** immediately to detect existing compromise.
- Apply **hardening guidance** provided by Cisco and security agencies.
## Detection
- **Indicators of Compromise (IOCs):** Attackers compromise SD-WANs to add a malicious rogue peer to achieve persistent access.
- **Detection Methods and Tools:** Defenders should urgently use the **ACSC-led Cisco SD-WAN Hunt Guide** to search for signs of compromise and malicious activity. Organizations finding compromise should report findings to relevant security authorities.
## References
- Vendor Advisories: Cisco Talos report concerning UAT-8616 exploitation.
- Relevant Links:
- ACSC-led Cisco SD-WAN Hunt Guide (Defanged link provided in context, consult official NCSC/ASD sites for the PDF).