logo

Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

ID: 360d9fcf-9d77-58b8-9bfc-42843966cf72

STIX ID: report--360d9fcf-9d77-58b8-9bfc-42843966cf72

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco disclosed that CVE-2026-20122 (arbitrary file overwrite, CVSS 7.1) and CVE-2026-20128 (information disclosure leading to DCA privileges, CVSS 5.5) affecting Catalyst SD-WAN Manager are being actively exploited; Cisco released patches across multiple 20.x releases and recommends immediate updates and network hardening. The report also references a recently exploited critical SD‑WAN zero-day (CVE-2026-20127, CVSS 10) attributed to a sophisticated actor tracked as UAT-8616, and additional critical fixes for Secure Firewall Management Center CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.