A critical authentication bypass vulnerability, CVE-2026-20127, affects the peering authentication mechanism in Cisco Catalyst SD-WAN Controller (formerly SD‑WAN vSmart) and Cisco Catalyst SD‑WAN Manager (formerly SD‑WAN vManage). The flaw allows an unauthenticated remote attacker to send crafted requests that bypass peering authentication and obtain an internal, high-privileged non-root administrative account.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

