Cisco SD-WAN fixes arrived with a warning to look for unauthorized changes.
What happened. CERT-EU summarized Cisco advisories for critical and high-severity flaws in Catalyst SD-WAN controllers and SD-WAN Manager. It noted that CVE-2026-20127 had been exploited since 2023.
Impact and confidence
Official coordination confirms the affected release ranges and exploitation concern. Local compromise requires evidence from each environment.
Defensive takeaway
Secure forensic evidence, review configuration for unexpected accounts or downgrade activity, restrict management access, and move to a fixed release.