CISA KEV Batch: Cisco SD-WAN Manager Auth Bypass + TeamCity + PaperCut, Lace Tempest Attribution
CISA simultaneously added eight vulnerabilities to KEV spanning three distinct product families with separate exploitation histories: Cisco Catalyst SD-WAN Manager, JetBrains TeamCity, and PaperCut. The triage ranking's claim of a 'Cisco SD-WAN vulnerability with EPSS 0.930' is incorrect — that EPSS belongs to CVE-2024-27198 (JetBrains TeamCity, with a public exploit via EDB-52411 already in KEV since March 2024), not to any SD-WAN CVE. The operationally significant new entry is CVE-2026-20127 (Cisco Catalyst SD-WAN Controller and Manager, EPSS 0.397, KEV confirmed), a network management-plane vulnerability associated with Cl0p and Lace Tempest — consistent with that cluster's established pattern of targeting managed infrastructure. A separate BleepingComputer entry notes CISA issued a compressed four-day remediation window for CVE-2026-20122, suggesting fresh exploitation intelligence rather than a retrospective KEV update. Sibling story 6536 covers a specific discrepancy in this batch: CVE-2026-20133 was flagged as exploited by CISA ahead of Cisco's own advisory acknowledgment, sharing Lace Tempest attribution and the same CVE set.
The compound nature of this KEV batch obscures the actual risk profile: TeamCity CVE-2024-27198 was already well-burned by late 2024 and its re-appearance likely reflects ongoing use rather than a new campaign; the Cisco SD-WAN entries are the genuinely new operational concern. Management-plane access to an SD-WAN fabric is a lateral movement multiplier — it's not just one network segment, it's the routing control plane for potentially thousands of devices. Lace Tempest's pivot from managed file transfer (MOVEit, GoAnywhere) toward network infrastructure management is worth tracking as a targeting evolution.
Lace Tempest/Cl0p's multi-year arc — MOVEit (2023), GoAnywhere (2023), now network management infrastructure — is a deliberate climb up the trust stack from file-transfer appliances into routing-control planes. The TeamCity CVE in this batch is old news being reprinted; the SD-WAN entries are the operationally new material. Treat CVE-2026-20133 as confirmed exploited regardless of where Cisco's advisory language sits today — CISA fronting exploitation ahead of the vendor historically reflects federal incident telemetry, not speculation.