CVE-2026-20126Disclosure(cisco / catalyst_sd-wan_manager)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-648

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-25); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-25: 2Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 2Mentions · 2026-04-22: 1Active Exploitation · 2026-03-05: 1Patch / Workaround · 2026-03-05: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 2Technical Details · 2026-04-22: 102-2502-2803-0303-0504-22
Signal classification4 categories
Disclosure
457.1%
General
114.3%
Active Exploitation
114.3%
Exploit
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure2
2026-02-281
Disclosure1
2026-03-031
General1
2026-03-052
Active Exploitation1Exploit1
2026-04-221
Disclosure1
Full discourse7 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Cisco Catalyst SD-WAN Vulnerabilities CVE-2026-20122/CVE-2026-20126/CVE-2026-20128/CVE-2026-20129/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 『Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、攻撃者が影響を受けるシステムにアクセスし、root権限に昇格し、機密情報にアクセスして任意のファイルを上書きできる可能性があります。』

    Post summary

    Cisco has disclosed multiple vulnerabilities in SD‑WAN Manager that could enable attackers to obtain root privileges and alter files, with no evidence of active exploitation or PoC provided.

    0301322.3K
    11.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20129 ❗ CVE-2026-20127 ❗ CVE-2026-20126 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-10/ https://t.co/RlhGyfevBO

    Post summary

    The post lists three Cisco CVEs and provides a link for more information, but offers no further details or context.

    03040326
    6.6K followersView on X
  • FirstPassLab@Felix1325456
    Active Exploitation

    3 Cisco SD-WAN CVEs actively exploited in 8 days. Here's the scorecard: CVE-2026-20127 — CVSS 10.0 — Auth bypass zero-day — Exploited since 2023 CVE-2026-20128 — CVSS 5.5 — DCA credential leak — Exploited (confirmed March 5) CVE-2026-20122 — CVSS 7.1 — File overwrite → privesc — Exploited (confirmed March 5) CVE-2026-20129 — CVSS 9.8 — API auth bypass → netadmin — Not yet CVE-2026-20126 — CVSS 7.8 — REST API → root — Not yet The pattern here is wild: • A CVSS 5.5 "Medium" flaw is being actively exploited while a CVSS 9.8 "Critical" isn't (yet) • That's because attackers chain vulnerabilities — a "medium" credential leak becomes devastating when it enables lateral movement • UAT-8616 exploited CVE-2026-20127 for 3 YEARS before it was discovered • CISA issued Emergency Directive ED 26-03 — that's federal agencies ordered to patch immediately • Google GTIG reported 90 zero-days exploited in 2025, half targeting enterprise infra The lesson: CVSS scores alone don't predict real-world risk. Context and chaining matter more. 5 CVEs. 0 workarounds. Patch is the only path. #CCIE #CiscoSDWAN #NetworkSecurity #Cisco #Networking #CyberSecurity #CISA

    Post summary

    The post details that three Cisco SD‑WAN CVEs are actively exploited and that no workarounds exist, prompting a CISA Emergency Directive and emphasizing patching as the sole mitigation, while highlighting that CVSS scores alone underestimate real‑world risk.

    00000136
    10 followersView on X
  • FirstPassLab@Felix1325456
    Exploit

    Cisco SD-WAN attack chain breakdown that every network engineer should understand: The UAT-8616 threat actor isn't using single exploits. They're chaining vulnerabilities like this: 1. CVE-2026-20128 (DCA credential exposure) → Read the DCA password from the local filesystem 2. Use stolen DCA creds to pivot to other SD-WAN Manager nodes 3. CVE-2026-20122 (arbitrary file overwrite via API) → Upload malicious files, gain vmanage user privileges 4. CVE-2026-20126 (REST API privesc) → Escalate to root They also chain CVE-2026-20127 (CVSS 10.0 auth bypass) with CVE-2022-20775 (an OLD CLI privesc from 2022) — and then DOWNGRADE the device software to re-introduce already-patched vulns. Quick hardening checklist while you plan your patch: • Block internet access to vManage/vSmart — restrict to known IPs • Disable HTTP on vManage web UI (HTTPS only) • Send logs to external SIEM (attackers modify local system scripts) • Monitor for unexpected software version changes • Audit API access logs for unusual auth patterns check your version: vmanage# show version Patch targets: 20.9.x → 20.9.8.2 20.12.x → 20.12.5.3 or 20.12.6.1 20.13-20.15 → 20.15.4.2 20.16-20.18 → 20.18.2.1 No workarounds exist. Patch is the only fix. #CCIE #CiscoSDWAN #Networking #NetworkSecurity #CiscoSecurity #SDWan

    Post summary

    The post outlines how attackers chain multiple Cisco SD‑WAN CVEs, provides hardening steps and exact patch versions, but gives no PoC or exploit code.

    0000035
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20126 A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating … https://www.cve.org/CVERecord?id=CVE-2026-20126

    Post summary

    The text announces a privilege‑escalation vulnerability in Cisco Catalyst SD-WAN Manager that allows local low‑privilege attackers to gain root access.

    00000197
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20126 - High A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerabi... https://www.thehackerwire.com/vulnerability/CVE-2026-20126/ https://t.co/EwOwffiKVt

    Post summary

    The post announces a high‑severity vulnerability in Cisco Catalyst SD-WAN Manager that permits local privilege escalation from low privileges to root on the underlying operating system.

    0000056
    115 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-20126** pertains to a security flaw in Cisco Catalyst SD-WAN Manager, where an attacker with low privileges and authenticated access can escalate privileges to gain root access on the underlying operating system. The root cause is an insufficient user authentication mechanism within the REST API, which allows unauthorized privilege escalation. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #Cisco https://cvetodo.com/cve/CVE-2026-20126

    Post summary

    The post describes a privilege escalation flaw in Cisco Catalyst SD-WAN Manager that lets low‑privileged authenticated users gain root access via an insecure REST API authentication mechanism.

    0000052
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.6--

Explore more