Cisco Talos is tracking the active exploitation of CVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges.
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/uat-8616-sd-wan/
![]()

