Looks like Cisco hit the jackpot.
-
Looks like Cisco hit the jackpot. This relates to CVE-2026-20127 and CVE-2022-20775.
New.
CISA PR: Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems https://www.cisa.gov/news-events/news/immediate-action-required-cisa-issues-emergency-directive-secure-cisco-sd-wan-systems
Mitigate Vulnerabilities in Cisco SD-WAN Systems https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems #CISA #infosec #Cisco
-
R relay@relay.infosec.exchange shared this topic on
-
Looks like Cisco hit the jackpot. This relates to CVE-2026-20127 and CVE-2022-20775.
New.
CISA PR: Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems https://www.cisa.gov/news-events/news/immediate-action-required-cisa-issues-emergency-directive-secure-cisco-sd-wan-systems
Mitigate Vulnerabilities in Cisco SD-WAN Systems https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems #CISA #infosec #Cisco
CVE-2026-20127 – an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
CVE-2022-20775 – a path traversal vulnerability that allows an authenticated, local attacker to gain elevated privileges and execute arbitrary commands as root.