Public exploitation evidence

CVE-2026-20127

As of 2026-07-28, CVE-2026-20127 has substantial public exploitation evidence: listed in CISA KEV and listed in ENISA EUVD (exploited). Most recent observation: 2026-02-25.

Published to NVD: 2026-02-25.

Observation timeline

Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.

ObservationSourceDate
Listed in CISA KEV CISA KEV 2026-02-25 View →
Listed in ENISA EUVD (exploited) ENISA EUVD (Exploited) 2026-02-25 View →

Exposure class & technique

This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:

T1078 · Valid Accounts

Weakness (CWE)

The MITRE CWE weakness type classified for this exposure class:

CWE-287 · Improper Authentication

CISA KEV context

Remediation due date2026-02-27
Required actionPlease adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Known ransomware campaign use None recorded
Commercial assessment

ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.

Get the assessment →

Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.

Related CVEs

Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.

Look it up yourself

Get a free key and look up any CVE yourself.

New to this? See what an exposure signal is and how ESIP builds one.

Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-07-28