CVE-2026-20127

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 33 articles Published: 2026-02-25

EPSS Score

Source: FIRST.org · 2026-05-24
44.3%
probability
This CVE has a 44.3% probability of being exploited in the next 30 days.
0% Top 97.6th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
10.0
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

Affected Products

Cisco
Cisco Catalyst SD-WAN Manager
20.1.12 19.2.1 18.4.4 18.4.5 20.1.1.1 20.1.1

Attack Intelligence

Exploits & PoC

zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

PoC CVE-2026-20127 — zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

31
BugFor-Pings/CVE-2026-20127_EXP

Cisco Catalyst SD-WAN 身份验证绕过漏洞(CVE-2026-20127)利用EXP

4
yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE

PoC CVE-2026-20127 — yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE

2
gigachadusers/cve-2026-20127

PoC CVE-2026-20127 — gigachadusers/cve-2026-20127

0
abrahamsurf/sdwan-scanner-CVE-2026-20127

Cisco SD-WAN Exposure & Potential Vulnerability Scanner (Passive Fingerprinting) 2026

0
5 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 44.3%
CVSS v3.1 10.0
Mentions 33
Last Seen Jun 16, 2026

CNA Information

CNA Assigner
cisco
CNA Title
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Analyst Note

CVE-2026-20127 exhibits strong zero-day indicators: explicitly named as 'zero-day' in authoritative sources (TheHackerNews, Tenable-Research), exploitation documented since 2023 (years before February 2026 publication), and active exploitation in the wild confirmed by multiple trusted security sources including CERT-EU and BleepingComputer. The timing clearly shows exploitation preceded public disclosure.

Triage Info

Decided atMar 05, 2026
Published DateFeb 25, 2026