logo

Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access

ID: ae7fa839-840e-5ada-bc2c-99de7ec12622

STIX ID: report--ae7fa839-840e-5ada-bc2c-99de7ec12622

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cisco issued an urgent advisory for multiple critical vulnerabilities in Cisco Catalyst SD‑WAN Manager — led by CVE‑2026‑20129 (authentication bypass, CVSS 9.8) — that can allow unauthenticated attackers or low‑privilege users to gain netadmin/root access, overwrite system files, and steal plaintext credentials; CVE‑2026‑20122 and CVE‑2026‑20128 are reported as being actively exploited. Cisco recommends immediate upgrades to fixed releases (for example 20.9.8.2, 20.12.5.3, or 20.18.2.1), restricting internet access to the management portal, disabling unused services, and enforcing strict firewall rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.