Cisco warns of two more SD-WAN bugs under active attack
ID: e870f5e9-c070-5fd0-abc1-2231799270dc
STIX ID: report--e870f5e9-c070-5fd0-abc1-2231799270dc
Feed Name: The Register (Security)
Cisco confirmed active exploitation of two vulnerabilities in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20122 — authenticated arbitrary file overwrite; CVE‑2026‑20128 — information disclosure enabling DCA privileges). The advisory follows earlier warnings about SD‑WAN targeting (including CVE‑2022‑20775 and CVE‑2026‑20127), mentions potential activity by a sophisticated actor tracked as UAT‑8616, and urges customers to upgrade to fixed releases; Cisco provided few technical details or IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
