Skip to main content

Share story

Security

Canadian Centre for Cyber Security issues alert on Cisco Catalyst SD-WAN CVE-2026-20127 critical authentication flaw

Red maple leaf with numbers and other digital-related imagery laid over it. Image: Primary
The Canadian Centre for Cyber Security issued alert AL26-004 on February 25, 2026. The alert warns of active exploitation of Cisco Catalyst Software-Defined Wide Area Network devices. It was released in response to a Cisco security advisory issued the same day. Tracked as CVE-2026-20127, the vulnerability is a critical improper authentication flaw in the peering authentication process of Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. It could allow an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on affected systems. Cisco Catalyst SD-WAN Controller systems that have internet-exposed management or control planes and ports exposed are at risk of compromise. The vulnerability affects on-prem deployment as well as Cisco Hosted SD-WAN Cloud - Cisco Managed, Cisco Hosted SD-WAN Cloud - FedRAMP Environment, and Cisco Hosted SD-WAN Cloud. The Cyber Centre is aware of incidents involving the vulnerability. Reports indicate that malicious rogue peers were added to the configuration of affected organizations SD-WAN, allowing administrative access, persistence, and long-term access to SD-WAN networks. The Cyber Centre recommends that organizations upgrade affected Cisco Catalyst SD-WAN instances to a fixed version. It also recommends collecting artifacts including virtual snapshots and logs from SD-WAN technology, fully patching SD-WAN technology, hunting for evidence of compromise, and implementing Cisco SD-WAN hardening guidance. The hardening guidance addresses network perimeter controls, SD-WAN Manager access, control and data plane security, session timeout limits, and logging to a remote syslog server. Organizations are advised to review and implement the Cyber Centre's Top 10 IT Security Actions. Emphasis is placed on consolidating monitoring and defending internet gateways, patching operating systems and applications, hardening operating systems and applications, and isolating web-facing applications. Activity matching the alert should be reported via My Cyber Portal or to [email protected].
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Canadian Centre for Cyber Security and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

AI Capital
AI Capital

Chinese local governments offer incentives to AI filmmakers

Reuters reports that Chinese local governments are offering computing vouchers, rent waivers and dedicated funding to attract filmmakers using artificial intelligence. These incentives reduce the cost of computing and premises for...

Security AI
Security AI

GitHub Security Lab releases agent workflow for automated fuzz testing

GitHub Security Lab has published a workflow that uses an AI agent to set up and run fuzz tests for C and C++ projects. Given a repository, it selects functions to test, writes test harnesses, runs AFL++, checks which code the tes...

Infrastructure Security
Infrastructure Security

Polish officials suspect arson at facility used by Starlink

Polish officials suspect that a fire at an Exatel telecommunications facility used by Starlink was set deliberately. Firefighters were called to the site in Wola Krobowska, south of Warsaw, at around 9 p.m. Wednesday. Police and i...