logo

Cisco flags ongoing exploitation of two recently patched Catalyst SD-WAN flaws

ID: 0395186d-90fc-53dd-9cd1-c4f6caecbc60

STIX ID: report--0395186d-90fc-53dd-9cd1-c4f6caecbc60

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco warns that two recently patched Catalyst SD-WAN vulnerabilities (CVE-2026-20128 and CVE-2026-20122) are being actively exploited in the wild, enabling local or remote authenticated attackers to gain DCA privileges, overwrite arbitrary files via the SD-WAN Manager API, and escalate to root; Cisco Talos links the activity to a highly sophisticated actor tracked as UAT-8616 and notes related exploitation dating back to 2023. Patches were released and customers are strongly urged to upgrade affected Catalyst SD-WAN releases immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.