Cisco has updated a critical security advisory to include the Catalyst SD-WAN Validator, formerly known as vBond, as a product vulnerable to a maximum-severity flaw. This vulnerability, tracked as CVE-2026-20127, involves an improper authentication issue that allows attackers to gain administrative rights and reconfigure the SD-WAN fabric. When combined with a secondary path traversal bug, unauthorized actors can achieve persistent root access to affected networking instances.
Source