Skip to content
ThreatCluster

Critical Vulnerabilities in Cisco Catalyst SD-WAN Manager Exploited

First seen 21 Apr 2026, 09:24 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 22, 2026 at 09:05 UTC
  • •CVE-2026-20122 allows remote file overwriting with valid API credentials.
  • •CVE-2026-20128 enables unauthenticated access to DCA user privileges.
  • •Both vulnerabilities are actively exploited and should be patched immediately.

Two critical vulnerabilities, CVE-2026-20122 and CVE-2026-20128, have been identified in Cisco Catalyst SD-WAN Manager, both published on 2026-02-25. CVE-2026-20122 allows authenticated remote attackers to overwrite arbitrary files via the API, while CVE-2026-20128 permits unauthenticated remote attackers to gain DCA user privileges through a credential file exploit. Both vulnerabilities were added to the CISA KEV list on 2026-04-20 due to active exploitation. Affected systems include versions prior to 20.18 of Cisco Catalyst SD-WAN Manager. Attackers can exploit these vulnerabilities to escalate privileges and potentially compromise additional systems. Organizations using vulnerable versions are urged to apply updates immediately to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 169d ago How this analysis works

Timeline

2026-02-25
CVE-2026-20122 and CVE-2026-20128 published
2026-04-20
Both CVEs added to CISA KEV due to active exploitation
2026-04-21
Cisco confirms vulnerabilities and urges immediate patching

More articles in this cluster (2)

Following this threat?

Track CVE-2026-20122 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed