ThinkPatternGet the app
Story
TECHNOLOGY · FEB 26, 2026

CISA Mandates Federal Patching of Critical Cisco SD-WAN Flaw

The Cybersecurity and Infrastructure Security Agency ordered federal agencies to patch a critical Cisco Catalyst SD-WAN vulnerability exploited by hackers since 2023.

The Cybersecurity and Infrastructure Security Agency issued an emergency directive on February 25, 2026, requiring all civilian federal agencies to patch a critical zero-day vulnerability in Cisco Catalyst SD-WAN systems by February 27. Identified as CVE-2026-20127, the flaw carries a maximum severity rating of 10.0 and allows unauthenticated remote attackers to bypass authentication to gain administrative or root privileges.

Cisco confirmed the vulnerability has been exploited since at least 2023, targeting large enterprises and government entities in critical infrastructure sectors, including transportation and power grids. A sophisticated threat actor cluster designated as UAT-8616 leveraged the flaw to gain initial access and then deliberately downgraded software versions to exploit an older 2022 path traversal flaw, ensuring persistent root access across network fabrics.

In response to the imminent threat, security agencies from the Five Eyes alliance — including the United States, United Kingdom, Canada, Australia, and New Zealand — released a joint Hunt Guide to help defenders detect intrusions. Cisco released software updates to address the vulnerability, stating that no workarounds are available. If left unpatched, attackers can manipulate routing policies, introduce rogue peers, and maintain total visibility across an organization's network infrastructure.


Reported across 7 outlets
Actors
Cisco Systems, Inc.Cisco Talos

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play