Heise.De CISA Warns of Active Exploitation of Cisco Catalyst SD-WAN Vulnerabilities
Article Content
- •CISA added three Cisco vulnerabilities to its KEV catalog on April 20, 2026.
- •Organizations have until April 23, 2026, to implement mitigations or discontinue use of affected products.
- •Exploitation of these vulnerabilities could allow attackers to gain control over network management systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of three vulnerabilities in Cisco's Catalyst SD-WAN Manager, specifically CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133. These vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on April 20, 2026, with a tight remediation deadline set for April 23, 2026. The flaws allow attackers to gain unauthorized access to sensitive information and potentially take control of affected systems. Cisco has yet to confirm the active exploitation of CVE-2026-20133, although CISA has indicated evidence of exploitation. Organizations must implement mitigations immediately, or discontinue use of the affected product. CISA's Emergency Directive 26-03 outlines the necessary steps for federal agencies and private organizations to secure their networks. The vulnerabilities pose significant risks to network integrity, especially given the critical role of the Catalyst SD-WAN Manager in managing enterprise-wide area network infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track Cisco and CVE-2023-27351 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…