Cisco flags ongoing exploitation of two recently patched Catalyst SD-WAN flaws
ID: 0395186d-90fc-53dd-9cd1-c4f6caecbc60
STIX ID: report--0395186d-90fc-53dd-9cd1-c4f6caecbc60
Feed Name: Security Affairs
Cisco warns that two recently patched Catalyst SD-WAN vulnerabilities (CVE-2026-20128 and CVE-2026-20122) are being actively exploited in the wild, enabling local or remote authenticated attackers to gain DCA privileges, overwrite arbitrary files via the SD-WAN Manager API, and escalate to root; Cisco Talos links the activity to a highly sophisticated actor tracked as UAT-8616 and notes related exploitation dating back to 2023. Patches were released and customers are strongly urged to upgrade affected Catalyst SD-WAN releases immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
