InfoSec News Nuggets 02/27/2026

Cisco SD-WAN Zero-Day CVE-2026-20127 Has Been Actively Exploited Since 2023 — CISA Patch Deadline Is Today Cisco disclosed a maximum-severity (CVSS 10.0) authentication bypass flaw in its Catalyst SD-WAN Controller and Manager products, tracked as CVE-2026-20127, confirming the vulnerability has been actively exploited in the wild since at least 2023 — a three-year blind spot that allowed threat actors tracked as UAT-8616 to compromise controllers, insert rogue peers into targeted networks, and chain the exploit…
Read More