logo

Cisco flags more SD-WAN flaws as actively exploited in attacks

ID: fd737570-20ad-5078-be4a-19fa814a1441

STIX ID: report--fd737570-20ad-5078-be4a-19fa814a1441

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco warned that multiple Catalyst SD-WAN Manager vulnerabilities are being actively exploited, including a high-severity arbitrary file overwrite (CVE-2026-20122) and a medium-severity information disclosure flaw (CVE-2026-20128), and reiterated that a separate critical authentication bypass (CVE-2026-20127) has been exploited since at least 2023; the flaws allow attackers to compromise controllers, insert rogue peers, and move deeper into networks, prompting vendor patches and a U.S. CISA emergency directive for mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.