Cisco warns of critical SD-WAN security flaw which has been open since 2023



  • Cisco Catalyst SD-WAN zero-day (CVE-2026-20127) being exploited since 2023
  • Flaw allowed attackers to add rogue peers and manipulate network configs
  • CISA added bug to KEV catalog, ordering urgent patching; linked to threat group UAT-8616

“Highly sophisticated” threat actors have reportedly been exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN for over two years, the company has revealed.

Cisco’s cybersecurity arm, Talos, released a new report saying it observed a critical authentication vulnerability being actively exploited by crooks that used it to compromise controllers and add malicious rogue peers to target networks.


https://cdn.mos.cms.futurecdn.net/bLTg6GBXmrv6c5v7AJFPsT-1980-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img