Researchers warned that defenders may be underestimating the risk from Cisco SD-WAN flaws beyond the widely publicized zero-day CVE-2026-20127, particularly CVE-2026-20133, a high-severity issue tied to inadequate file system access restrictions. VulnCheck reported that public attention and detection efforts have focused too narrowly on CVE-2026-20127, even though proof-of-concept activity attributed to that bug appears to affect other vulnerabilities, including CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. Defused researchers said their telemetry supports that assessment, indicating that CVE-2026-20127 is generating heavy automated noise while activity involving CVE-2026-20133, if present, is likely quieter and easier to miss.
Broader reporting indicates the SD-WAN issue is part of a larger pattern of active exploitation across Cisco edge infrastructure, with multiple recently disclosed SD-WAN and firewall vulnerabilities already exploited in the wild. CyberScoop reported that five of nine Cisco flaws disclosed across firewalls and SD-WAN systems in recent weeks have seen exploitation, including two SD-WAN zero-days abused for years before discovery and three additional SD-WAN defects later confirmed under attack. The reporting also noted exploitation of a maximum-severity Cisco firewall management flaw by Interlock ransomware, underscoring that attackers are targeting management-plane and control-plane weaknesses in network-edge products that often serve as enterprise trust anchors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
CISA added Cisco Catalyst SD-WAN Manager vulnerability CVE-2026-20133 to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency ordered Federal Civilian Executive Branch agencies to secure affected systems by 2026-04-24 and follow Emergency Directive 26-03 and Cisco hardening guidance.
CISA added Cisco Catalyst SD-WAN Manager flaws CVE-2026-20128 and CVE-2026-20122 to its Known Exploited Vulnerabilities catalog after Cisco confirmed active exploitation. Federal agencies were given a remediation deadline in late April 2026, expanding U.S. government response beyond CVE-2026-20133 alone.
VulnCheck assessed that the high-severity Cisco Catalyst SD-WAN flaw CVE-2026-20133 may pose a greater immediate risk than the more publicized zero-day CVE-2026-20127. Defused researchers also said vulnerable SD-WAN devices were being targeted through multiple avenues and that CVE-2026-20133 exploitation may be quieter and easier to miss.
VulnCheck reported that a proof-of-concept published by ZeroZenX Labs for CVE-2026-20127 did not actually target that zero-day, but instead affected CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. The finding suggested defenders may be misjudging which SD-WAN vulnerabilities are most urgent.
Cisco recently disclosed nine vulnerabilities affecting SD-WAN and firewall management products, with five later confirmed as exploited in the wild. The disclosures included the zero-day CVE-2026-20127 and other SD-WAN flaws such as CVE-2026-20133.
Cisco released fixes in late February 2026 for CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 affecting Catalyst SD-WAN Manager. The vulnerabilities were later cited by CISA as actively exploited or included in its Known Exploited Vulnerabilities catalog.
CISA issued an emergency directive requiring federal executive branch agencies to assess and patch Cisco SD-WAN Manager systems after concerns about active exploitation. The directive elevated the urgency of the Cisco SD-WAN vulnerability situation for U.S. government networks.
Amazon Threat Intelligence said the Interlock ransomware group started exploiting a maximum-severity Cisco firewall management vulnerability before it was publicly disclosed. The exploitation reportedly began on January 26 and targeted firewall management infrastructure.
Two Cisco SD-WAN zero-day vulnerabilities were reportedly exploited in the wild for at least three years before Cisco disclosed them. This indicates long-running attacker access to SD-WAN management or control-plane systems prior to public awareness.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcecybersecuritydive.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.