HomeSecurityCisco: Active exploitation of two vulnerabilities in Catalyst SD-WAN Manager

Cisco: Two vulnerabilities in Catalyst SD-WAN Manager actively exploited

Cisco has revealed that two more vulnerabilities affecting Catalyst SD-WAN Manager (formerly SD-WAN vManage) are being actively exploited by cybercriminals .

Cisco Catalyst SD-WAN Manager

The vulnerabilities mentioned are the following:

– CVE-2026-20122 (CVSS score: 7.1) – An “ arbitrary file overwrite ” vulnerability, which could allow an authorized, remote attacker to overwrite arbitrary files on the local file system . Successful exploitation requires the attacker to have valid read-only credentials with API access to the affected system.

– CVE-2026-20128 (CVSS score: 5.5) – An information disclosurethat could allow an authorized, local attacker to gain Data Collection Agent (DCA) user privileges on an affected system. Successful exploitation requires the attacker to have valid vManage credentials on the affected system.

See also: MongoDB: Vulnerability allows servers to crash

Fixes for these security flaws were released by Cisco late last month, along with updates for CVE-2026-20126, CVE-2026-20129, and CVE-2026-20133:

  • Before version 20.91 – Transition to fixed release.
  • Version 20.9 – Fix in 20.9.8.2
  • Version 20.11 – Fix in 20.12.6.1
  • Version 20.12 – Fix in 20.12.5.3 and 20.12.6.1
  • Version 20.13 – Fix in 20.15.4.2
  • Version 20.14 – Fix in 20.15.4.2
  • Version 20.15 – Fix in 20.15.4.2
  • Version 20.16 – Fix in 20.18.2.1
  • Version 20.18 – Fix in 20.18.2.1

“ In March 2026, Cisco PSIRT was notified of active exploitation of vulnerabilities CVE-2026-20128 and CVE-2026-20122 ,” the networking equipment company said . The company did not expand on the scale of the activity or say who might be behind it.

See also: Google: Half of 2025's zero-days targeted businesses

Instant upgrade of Cisco Catalyst SD-WAN Manager

In light of the active exploit, users are urged to update their Catalyst SD-WAN Manager to a patched software version as soon as possible. They should also take steps to restrict access from unsecured networks, secure devices behind a firewall, disable HTTP for the Catalyst SD-WAN Manager management portal, disable network services such as HTTP and FTP if not required, change the default administrator password , and monitor log traffic for any unexpected traffic to and from the systems.

See also: Cisco Secure FMC: Vulnerability allows RCE attacks

The revelation comes a week after the company announced that a critical security vulnerability in Cisco Catalyst SD-WAN Controller and Catalyst SD-WAN Manager (CVE-2026-20127, CVSS score: 10.0) had been exploited by a highly sophisticated group. The threat actor is tracked as UAT-8616 and was attempting to establish permanent access to high-value organizations .

This week, Cisco also released updates to address two maximum severity vulnerabilities in the Secure Firewall Management Center (CVE-2026-20079 and CVE-2026-20131, CVSS scores: 10.0) that could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary Java code as root on an affected device.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS