Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities
ID: 3dae0ec2-f925-5efa-8367-797a5f3751df
STIX ID: report--3dae0ec2-f925-5efa-8367-797a5f3751df
Feed Name: Help Net Security
Threat Score
Cisco confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager (CVE-2026-20128 and CVE-2026-20122) that allow attackers with valid credentials to gain DCA/vmanage privileges or overwrite arbitrary files, and urged customers to upgrade; the report also notes additional Cisco fixes for Secure Firewall products and references a recently exploited zero-day (CVE-2026-20127) tied to a sophisticated actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
