Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

CISA orders federal agencies to patch Cisco SD-WAN flaws after active exploitation

Emergency directive ED 26-03, issued February 25, 2026, requires federal agencies to patch actively exploited Cisco SD-WAN vulnerabilities including an authentication bypass rated critical.

Malik Johnson, · February 28, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
Network operations engineers reviewing a rack of SD-WAN appliances

CISA issued emergency directive ED 26-03 on February 25, 2026, ordering federal civilian agencies to patch a set of actively exploited vulnerabilities in Cisco SD-WAN systems, led by CVE-2026-20127 — an authentication bypass that lets an unauthenticated remote attacker take over affected devices. CISA determined the flaws pose an unacceptable risk to federal networks, the standard threshold for an emergency directive, which carries mandatory deadlines rather than advisory timelines. The directive follows Cisco's own advisories and patches for the affected product line.

What do we know about the flaws?

Per CISA's directive, the vulnerabilities affect Cisco SD-WAN components, and CVE-2026-20127 is an authentication bypass with a critical CVSS score that allows an unauthenticated remote attacker to bypass authentication on affected systems. Coverage by Infosecurity Magazine noted the critical severity rating; a related flaw, CVE-2026-20131, was reported to affect Cisco's Secure Firewall Management Center in the same patch cycle. Exploitation of at least one flaw in the set is confirmed — that is what distinguishes an emergency directive from routine advisories — with fixes available from Cisco for all affected versions listed in the vendor's advisory.

Who is affected beyond the government?

Any organization running affected Cisco SD-WAN versions, not just federal agencies. Emergency directives bind only federal civilian networks, but CISA publishes them partly because the same exposure exists across private networks — and internet-facing management interfaces of SD-WAN and firewall infrastructure are a top initial-access route for ransomware crews as well as espionage actors. State and local government, healthcare, and mid-size enterprises run plenty of the affected hardware.

What should you do now?

  1. Identify affected systems. Inventory Cisco SD-WAN and vManage deployments, including management interfaces exposed to the internet.
  2. Apply Cisco's fixed versions listed in its advisory — patching is the primary remediation, and there is no indication that configuration changes alone close CVE-2026-20127.
  3. Hunt for signs of compromise before assuming a clean bill: review authentication logs for anomalous sessions around the management plane, unexpected account creation, and config changes. CISA's directive requires agencies to report indicators of compromise.
  4. Get management interfaces off the internet. If vManage or device controllers are reachable from outside, restrict them to a management VPN or allow-list now — the next directive like this is a matter of when, not if.
  5. Track the KEV catalog. These CVEs belong to CISA's Known Exploited Vulnerabilities catalog, whose patch deadlines apply to federal agencies and serve as the de facto deadline for everyone else.

ED 26-03 is the first emergency directive of 2026, continuing a cadence that has accelerated since 2023 — edge devices under active exploitation are now the dominant trigger, and patch windows measured in days are the new normal.

Frequently Asked Questions

What is CISA emergency directive ED 26-03?
A binding order issued February 25, 2026 requiring U.S. federal civilian agencies to patch actively exploited vulnerabilities in Cisco SD-WAN systems — led by critical authentication bypass CVE-2026-20127 — within set deadlines and to report compromise indicators.
Does the directive apply to private companies?
Not legally — emergency directives bind federal civilian agencies. But the exploited flaws affect any organization running the affected Cisco versions, and CISA publishes these directives so private networks patch the same exposure on similar timelines.
Is there a workaround instead of patching?
No configuration-only workaround is indicated for CVE-2026-20127; the fix is applying Cisco's patched versions. Restricting management interfaces from the internet reduces exposure but does not replace patching.