Critical Vulnerabilities in Cisco Catalyst SD-WAN Manager Exploited
Article Content
- •CVE-2026-20122 allows remote file overwriting with valid API credentials.
- •CVE-2026-20128 enables unauthenticated access to DCA user privileges.
- •Both vulnerabilities are actively exploited and should be patched immediately.
Two critical vulnerabilities, CVE-2026-20122 and CVE-2026-20128, have been identified in Cisco Catalyst SD-WAN Manager, both published on 2026-02-25. CVE-2026-20122 allows authenticated remote attackers to overwrite arbitrary files via the API, while CVE-2026-20128 permits unauthenticated remote attackers to gain DCA user privileges through a credential file exploit. Both vulnerabilities were added to the CISA KEV list on 2026-04-20 due to active exploitation. Affected systems include versions prior to 20.18 of Cisco Catalyst SD-WAN Manager. Attackers can exploit these vulnerabilities to escalate privileges and potentially compromise additional systems. Organizations using vulnerable versions are urged to apply updates immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-20122 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…