logo

Cisco warns of two more SD-WAN bugs under active attack

ID: e870f5e9-c070-5fd0-abc1-2231799270dc

STIX ID: report--e870f5e9-c070-5fd0-abc1-2231799270dc

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-03-06

Date Updated: 2026-04-26

Author: Carly Page

...
...

Cisco confirmed active exploitation of two vulnerabilities in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20122 — authenticated arbitrary file overwrite; CVE‑2026‑20128 — information disclosure enabling DCA privileges). The advisory follows earlier warnings about SD‑WAN targeting (including CVE‑2022‑20775 and CVE‑2026‑20127), mentions potential activity by a sophisticated actor tracked as UAT‑8616, and urges customers to upgrade to fixed releases; Cisco provided few technical details or IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.