Cisco flags more SD-WAN flaws as actively exploited in attacks
ID: fd737570-20ad-5078-be4a-19fa814a1441
STIX ID: report--fd737570-20ad-5078-be4a-19fa814a1441
Feed Name: Bleeping Computer
Cisco warned that multiple Catalyst SD-WAN Manager vulnerabilities are being actively exploited, including a high-severity arbitrary file overwrite (CVE-2026-20122) and a medium-severity information disclosure flaw (CVE-2026-20128), and reiterated that a separate critical authentication bypass (CVE-2026-20127) has been exploited since at least 2023; the flaws allow attackers to compromise controllers, insert rogue peers, and move deeper into networks, prompting vendor patches and a U.S. CISA emergency directive for mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
