にゃん☆たく/takumi.a[verified]@taku888infinityDisclosure
Cisco has publicly disclosed multiple CVEs affecting its Catalyst SD‑WAN Manager that enable privilege escalation and file overwrites; the advisory directs readers to a Cisco security page but does not provide immediate patches or exploitation details.
piyokango[verified]@piyokangoActive Exploitation
The announcement confirms that CISA has added multiple CVEs to its KEV catalog after observing real‑world exploitation, offering vendor advisories and mitigation guidance but no PoC or exploitation code.
The Cyber Security Hub™[verified]@TheCyberSecHubPatch
The tweet announces a Cisco warning about SD‑WAN Manager exploitation and notes that 48 firewall vulnerabilities will be patched, but it does not provide PoCs, active exploitation evidence, or detailed technical data.
Adam[verified]@seoscottsdaleActive Exploitation
The advisory confirms that CVE‑2026‑20122 (file overwrite) and CVE‑2026‑20128 (info disclosure) in Cisco SD‑WAN Manager are actively exploited in the wild, with no workarounds and an urgent upgrade required.
Wasteland[verified]@wastelandweeklyActive Exploitation
CVE‑2026‑20127 is a zero‑day authentication bypass in Cisco Catalyst SD‑WAN that is actively exploited in the wild; users are advised to patch immediately.
Machina Record[verified]@MachinaRecordActive Exploitation
The post reports that two exploits for Cisco Catalyst SD‑WAN CVEs have been uncovered and that CISA has added three older Apple vulnerabilities to its KEV catalog.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The message lists multiple CVEs affecting Cisco Catalyst SD‑WAN Manager versions below 20.18, notes that CISA KEV federal deadlines have passed, and indicates that the vulnerabilities are being actively exploited in the wild.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The post confirms that CVE-2026-20133 is being actively exploited in the wild against Cisco Catalyst SD-WAN Manager, with no mention of a PoC, exploit tool, patch, or false-positive status.