Cybersecurity & Privacy — 2026-03-17
CISA Issues Emergency Directive 26-03: Federal Agencies Must Inventory and Patch SD-WAN Systems
CISA issued Emergency Directive 26-03 requiring all federal civilian agencies to inventory Cisco SD-WAN systems, apply mitigations for CVE-2026-20127 and CVE-2022-20775, and assess networks for indicators of compromise. The directive follows evidence that a "highly sophisticated" threat actor, likely state-backed given the exploitation chain, compromised SD-WAN infrastructure at multiple agencies. The order comes as CISA operates at 38% capacity following DHS staff reductions.
Analysis
The March 16 digest covered the underlying Cisco SD-WAN zero-day (CVSS 10). CISA's elevation to an Emergency Directive indicates confirmed federal agency compromise. CISA operates at 38% capacity, a gap tracked across multiple digests.
The March 16 digest covered the underlying Cisco SD-WAN zero-day (CVSS 10). CISA's elevation to an Emergency Directive indicates confirmed federal agency compromise. CISA operates at 38% capacity, a gap tracked across multiple digests.