Under Attack: Cisco Urges Immediate Action as Hackers Actively Exploit SD-WAN Manager Flaws
ID: 5d87353b-2bc0-5c6f-b076-10c1438dc756
STIX ID: report--5d87353b-2bc0-5c6f-b076-10c1438dc756
Feed Name: securityonline.info
Threat Score
Cisco warns that two vulnerabilities in the Catalyst SD‑WAN Manager are being actively exploited: CVE‑2026‑20122 allows an authenticated attacker with read‑only API access to overwrite arbitrary files and escalate to vmanage privileges, and CVE‑2026‑20128 exposes plaintext DCA credentials enabling lateral movement; Cisco provides fixed releases and strongly recommends immediate upgrades.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
