patch&proof.
← The dispatch

network-control / Source brief

Cisco SD-WAN fixes arrived with a warning to look for unauthorized changes

CERT-EU summarized Cisco advisories for critical and high-severity flaws in Catalyst SD-WAN controllers and SD-WAN Manager. It noted that CVE-2026-20127 h…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Cisco SD-WAN fixes arrived with a warning to look for unauthorized changes.

What happened. CERT-EU summarized Cisco advisories for critical and high-severity flaws in Catalyst SD-WAN controllers and SD-WAN Manager. It noted that CVE-2026-20127 had been exploited since 2023.

Impact and confidence

Official coordination confirms the affected release ranges and exploitation concern. Local compromise requires evidence from each environment.

Defensive takeaway

Secure forensic evidence, review configuration for unexpected accounts or downgrade activity, restrict management access, and move to a fixed release.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2026-02-26
Event date
2026-02-25
Site publication
Unpublished · local review
Multiple Vulnerabilities in Cisco Products
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval