CVE-2026-20128Active Exploitation(cisco / catalyst_sd-wan_manager)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-23. Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-257

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • Active exploitation appears in 52 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 62 mentions across 17 observed days

What's happening

  • Active exploitation reported across 52 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 31 signals
  • Technical details provided in 30 signals
  • General: 6 classified signals
  • Disclosure: 3 classified signals
  • Peaked 14d ago at 17 mentions (2026-03-05); latest day: 2
  • 62 total mentions across 17 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline62 mentions / 17d
0491317Mentions · 2026-02-25: 1Mentions · 2026-02-28: 1Mentions · 2026-03-05: 17Mentions · 2026-03-06: 11Mentions · 2026-03-07: 5Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-03-20: 1Mentions · 2026-04-20: 3Mentions · 2026-04-21: 5Mentions · 2026-04-22: 2Mentions · 2026-04-23: 2Mentions · 2026-04-28: 3Mentions · 2026-05-05: 3Mentions · 2026-06-07: 1Mentions · 2026-06-14: 2PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-07: 1Active Exploitation · 2026-03-05: 17Active Exploitation · 2026-03-06: 11Active Exploitation · 2026-03-07: 5Active Exploitation · 2026-03-09: 2Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 3Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-23: 2Active Exploitation · 2026-04-28: 2Active Exploitation · 2026-05-05: 3Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-14: 2Patch / Workaround · 2026-03-05: 13Patch / Workaround · 2026-03-06: 7Patch / Workaround · 2026-03-07: 5Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-06-07: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 11Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-20: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-28: 2Technical Details · 2026-06-14: 102-2502-2803-0503-0603-0703-0903-1003-1603-2004-2004-2104-2204-2304-2805-0506-0706-14
Signal classification5 categories
Active Exploitation
4979.0%
General
69.7%
Disclosure
34.8%
Patch
34.8%
Exploit
11.6%
Referenced assets60 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-251
General1
2026-02-281
Disclosure1
2026-03-0517
Active Exploitation15Patch2
2026-03-0611
Active Exploitation11
2026-03-075
Active Exploitation4Exploit1
2026-03-093
Active Exploitation2General1
2026-03-101
Active Exploitation1
2026-03-161
Active Exploitation1
2026-03-201
Disclosure1
2026-04-203
Active Exploitation1General1Patch1
2026-04-215
Active Exploitation3General2
2026-04-222
Active Exploitation1Disclosure1
2026-04-232
Active Exploitation2
2026-04-283
Active Exploitation2General1
2026-05-053
Active Exploitation3
2026-06-071
Active Exploitation1
2026-06-142
Active Exploitation2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Cisco confirms active exploitation of two Catalyst SD-WAN Manager flaws. ▶ CVE-2026-20122 enables arbitrary file overwrite via API credentials. ▶CVE-2026-20128 can expose data and grant DCA privileges after login. 🔗 Read → https://thehackernews.com/2026/03/cisco-confirms-active-exploitation-of.html

    Post summary

    Cisco confirmed that CVE‑2026‑20122 and CVE‑2026‑20128 are being actively exploited in the wild, with one flaw enabling arbitrary file overwrite and the other exposing data and granting privileged access.

    32237377.9K
    1.1M followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Cisco Catalyst SD-WAN Vulnerabilities CVE-2026-20122/CVE-2026-20126/CVE-2026-20128/CVE-2026-20129/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 『Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、攻撃者が影響を受けるシステムにアクセスし、root権限に昇格し、機密情報にアクセスして任意のファイルを上書きできる可能性があります。』

    Post summary

    The advisory announces several CVEs in Cisco Catalyst SD-WAN Manager that could allow attackers to gain root access and overwrite files; no proof of concept or exploitation details are provided.

    0301322.3K
    11.7K followersView on X
  • SECUREU@secureu_in
    Active Exploitation

    Another Cisco nightmare. Two more SD-WAN Manager vulnerabilities under active attack. CVE-2026-20122 & CVE-2026-20128. Web shells already deployed. 🚨 https://t.co/m1ZdO042Xl

    Post summary

    The tweet reports that two Cisco SD‑WAN Manager CVEs (CVE‑2026‑20122 and CVE‑2026‑20128) are currently being exploited in the wild, with web shells already deployed.

    12030152
    235 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/20追加) 🛡️No.1571 CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability ✅概要 ・深刻度:重要 7.1 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:特権 API の不適切な使用 (CWE-648) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の API において、認証されたリモートの攻撃者がローカルファイルシステム上の任意のファイルを上書きできる脆弱性。悪用には影響を受けるシステムに対する API アクセス権を持つ有効な読み取り専用資格情報が必要。事前認証されていない攻撃者により、任意ファイルの上書きに加え、vmanage ユーザー権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・攻撃者が API アクセス権を持つ有効な読み取り専用資格情報を有していること。 ________________________________________ ✅悪用時影響 ・ローカルファイルシステム上の任意のファイルを上書き ・vmanage ユーザー権限を取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20122 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems 🛡️No.1572 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:情報漏えい (CWE-200) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager において、事前認証されていない攻撃者により、機密情報を摂取される恐れがある。原因はファイルシステムのアクセス制限が不十分なためで、攻撃者は対象システムのAPIにアクセスして悪用。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・該当システム上の機密情報を閲覧 ・基盤となるオペレーティングシステム上の機密情報を読み取られる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 🛡️No.1573 CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / VulnCheck (CNA) ・種別:パス・トラバーサル、 危険なタイプのファイルの無制限アップロード(CWE-22,CWE-434) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) Kentico Xperience 13.0.178以前に、認証済の攻撃者によって、Staging Sync Server経由で任意の相対パスへデータをアップロード可能な脆弱性が存在。パストラバーサルと任意ファイルアップロードを経てサーバサイドで実行可能なコンテンツ配置によるリモートコード実行を行われる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Kentico Xperience 13.0.177以前が稼働していること。 ・Staging Serviceが有効であること。 ・Staging Serviceがユーザー名/パスワード認証で構成されていること。 ・攻撃者がStaging Sync Serverに対する有効な認証済み権限を有すること。 ________________________________________ ✅悪用時影響 ・任意ファイルアップロードにより、サーバサイドで実行可能なコンテンツを配置 ・リモートコードの実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-2749 https://devnet.kentico.com/download/hotfixes 🛡️No.1574 CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / NVD ・種別:不適切な認証 (CWE-287) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N PaperCut NG/MFのApplication Serverにおいて、事前認証されていない攻撃者により、リモートからユーザー情報を取得される恐れがある。対象となる情報に、PaperCutは、ユーザー名、氏名、メールアドレス、部署情報、カード番号に加え、内部作成ユーザーのハッシュ化パスワードを取得され得ると報告。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・PaperCut NG/MFのApplication Serverが脆弱バージョンで稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証を回避して、ユーザー名、氏名、メールアドレス、部署情報、カード番号などのユーザー情報を取得 ・内部作成ユーザーに限り、ハッシュ化されたパスワードを取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず (GitHub) ・ITW:未確認 (PaperCut) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-27351 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 🛡️No.1575 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability ✅概要 ・深刻度:注意6.1 (CVSS Base) / CISA-ADP ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の Classic UI において、HTMLコンテンツの不十分なサニタイズにより、ユーザーのセッション内で任意のJavaScriptを実行される恐れがある。細工されたタグ構造や属性値に含まれる @ import ディレクティブなどのスクリプト注入ベクトルが原因。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の脆弱バージョンが稼働していること。 ・攻撃者が細工した電子メールメッセージを対象ユーザーに閲覧させること。 ・Classic UI で細工された電子メールメッセージが閲覧されること。 ・追加の利用者操作は不要。 ________________________________________ ✅悪用時影響 ・ユーザーのセッション内で任意のJavaScriptを実行 ・機微情報への不正アクセスにつながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-48700 https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories 🛡️No.1576 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:復元可能な形式でのパスワード保存 (CWE-257) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の Data Collection Agent(DCA)機能において、事前認証されていない攻撃者により、リモートから DCA ユーザー権限を取得される恐れがある。影響を受けるシステム上に DCA ユーザーの認証情報ファイルが存在することで、細工された HTTP 要求により当該ファイルを読み取られる可能性。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・DCA パスワードを含むファイルを読み取られる ・別の影響を受けるシステムへアクセスされ、DCA ユーザー権限を取得される ・機密情報へアクセスされる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20128 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v   🛡️No.1577 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Quest KACE Systems Management Appliance (SMA) には、事前認証されていない攻撃者により、正規ユーザーになりすませる認証回避の脆弱性が存在。SSO認証処理に起因し他脆弱性で、完全な管理者乗っ取りをされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Quest KACE Systems Management Appliance (SMA) の脆弱バージョンが稼働していること。 ・対象機器がネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・正当な認証情報なしに正規ユーザーになりすまされる ・完全な管理者権限を取得される ・アプライアンスを全面的に掌握される ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Arctic Wolf は、2026年3月9日の週から、インターネット公開された未パッチのKACE SMAに対するCVE-2025-32975悪用の可能性がある不正活動を顧客環境で観測したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32975 https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 🛡️No.1578 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.3 (CVSS Base) / JetBrains s.r.o. (CNA) (NVD) ・種別:相対パストラバーサル (CWE-23) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (NVD) JetBrains TeamCity 2023.11.4未満に相対パストラバーサルの脆弱性が存在。事前認証されていない攻撃者により、HTTP(S)経由で認証チェックを回避し、TeamCityサーバの管理権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・TeamCity On-Premises 2023.11.3以前が稼働していること。 ・攻撃者が対象のTeamCityサーバへHTTP(S)アクセス可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証チェックを回避され、限定的な管理者アクションを実行される ・TeamCityサーバの管理権限を取得される ・機密情報の取得、設定情報の改変、サービス影響につながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み (NVD) ・ITW:確認済み。トレンドマイクロは、CVE-2024-27198およびCVE-2024-27199を悪用しようとする攻撃者活動を確認したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-27199 https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post catalogues several CVEs, some of which have been confirmed as actively exploited by security teams, while also providing mitigation guidance and detailed technical information, but lacks publicly available PoC or exploit code.

    000415.9K
    43.6K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Patch

    Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities https://www.helpnetsecurity.com/2026/03/05/cisco-cve-2026-20128-cve-2026-20122-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Cisco alerts stakeholders to exploitation of SD‑WAN Manager via CVE-2026-20128 and CVE-2026-20122, while announcing fixes for 48 additional firewall vulnerabilities.

    01040520
    193.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 تحذير من Cisco: استغلال لثغرات حرجة في SD-WAN Manager أصدرت Cisco تحذيرًا أمنيًا عاجلاً بشأن استغلال لثغرتين حرجتين ضمن منتجها Catalyst SD-WAN Manager (بما في ذلك CVE-2026-2256 و CVE-2026-20128). تتيح هذه الثغرات للمهاجمين تنفيذ عمليات استغلال نشطة في البيئات التشغيلية، ما يشكل تهديدًا مباشرًا للأنظمة المتأثرة وقد يؤدي إلى اختراقها. تحث Cisco المستخدمين بشدة على اتخاذ إجراءات فورية للتخفيف من المخاطر. 🔗 للمزيد: https://securityonline.info/under-attack-cisco-urges-immediate-action-as-hackers-actively-exploit-sd-wan-manager-flaws/

    Post summary

    Cisco warns that the CVE‑2026‑2256 and CVE‑2026‑20128 flaws in its SD‑WAN Manager are being actively exploited and urges users to take immediate mitigation measures.

    0003084
    60 followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Cisco warns that two vulnerabilities (CVE-2026-20122 and CVE-2026-20128) in its Catalyst SD-WAN Manager are being actively exploited. Update immediately. #Cisco #CyberSecurity #SDWAN #CVE #ActiveExploitation #NetworkSecurity #InfoSec #PatchAlert https://securityonline.info/under-attack-cisco-urges-immediate-action-as-hackers-actively-exploit-sd-wan-manager-flaws/

    Post summary

    Cisco alerts that CVE‑2026‑20122 and CVE‑2026‑20128 in Catalyst SD‑WAN Manager are actively exploited, urging users to patch immediately.

    01011240
    10.5K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/04/20:Cisco Catalyst SD-WAN Manager の脆弱性 CVE-2026-20122/20128/20133 を登録 https://iototsecnews.jp/2026/04/21/cisa-alerts-defenders-to-exploited-cisco-catalyst-sd-wan-manager-security-flaws/ 今回の Cisco Catalyst SD-WAN Manager に関する警告は、主に三つの脆弱性が原因となっています。機密情報が露出してしまう CVE-2026-20133 、不適切なファイル処理により特権 API が悪用される CVE-2026-20122 、そしてパスワードが復元可能な形式で保存されていた CVE-2026-20128 です。これらが組み合わさることで、遠隔の攻撃者に管理権限を奪われ、システムの設定を自由に書き換えられるリスクが生じています。特に、本来守られるべき認証情報の管理不備や API の処理の甘さが、攻撃者にとっての大きな突破口となっています。ご利用のチームは、ご注意ください。 #CatalystSDWANManager #CISA #Cisco #CVE202620122 #CVE202620128 #CVE202620133 #Exploit #KEV #Vulnerability

    Post summary

    CISA’s KEV alert warns that three CVEs in Cisco Catalyst SD-WAN Manager allow remote attackers to gain administrative control through exposed secrets, privilege API abuse, and recoverable passwords, indicating active exploitation in the wild.

    01001167
    486 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    🚨 Actively Exploited — Cisco SD-WAN Manager CVE-2026-20122 (file overwrite) CVE-2026-20128 (info disclosure) No workarounds. Upgrade immediately. Official Cisco advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v French Government CERT-FR (updated yesterday) also confirms in-the-wild attacks. #CyberSecurity #SDWAN #Cisco Have you patched yet? 👀

    Post summary

    The post highlights that CVE‑2026‑20122 and CVE‑2026‑20128 are actively exploited, urging users to apply Cisco’s patch immediately, supported by an official advisory and confirmation from French CERT.

    1100092
    12.5K followersView on X
  • Wasteland@wastelandweekly
    Active Exploitation

    CVE-2026-20127 is a zero-day auth bypass in Cisco Catalyst SD-WAN being actively exploited right now. No auth required. Two more CVEs (CVE-2026-20128 + CVE-2026-20122) confirmed in the wild same week. If you run SD-WAN, patch yesterday.

    Post summary

    The post claims an active zero‑day authentication bypass (CVE‑2026‑20127) in Cisco Catalyst SD‑WAN, with related CVEs confirmed in the wild, and urges immediate patching.

    10010119
    5 followersView on X
  • X Sec - Comunidad de Hackers@comunidadxsec
    Active Exploitation

    Cisco confirmó explotación activa de CVE-2026-20122 y CVE-2026-20128 en Catalyst SD-WAN Manager (vManage). Qué permiten, qué versiones corrigen y qué hacer hoy . https://drplaga.sh/cisco-catalyst-sd-wan-manager-dos-cves-bajo-explotacion-activa-cve-2026-20122-cve-2026-20128/ #DrPlaga.sh #Cisco #SDWAN #vManage #CVE #Exploitation #ThreatHunting #NetworkSecurity https://t.co/6XDpvmtj8K

    Post summary

    The tweet confirms that CVE-2026-20122 and CVE-2026-20128 are being actively exploited in Cisco Catalyst SD-WAN Manager, and it references information on which versions provide fixes.

    0101071
    121 followersView on X
  • Ethical Hacking Consultores@EHCGroup
    Active Exploitation

    Cisco advierte sobre la explotación de SD-WAN Manager y corrige 48 vulnerabilidades de firewall. Los hackers ya están explotando activamente dos fallos críticos (CVE-2026-20128 y CVE-2026-20122). Si usas equipos Cisco parcha ahora antes de que sea tarde. https://www.linkedin.com/pulse/cisco-advierte-sobre-la-explotaci%C3%B3n-de-sd-wan-manager-y-corrige-ullxe

    Post summary

    The post warns that attackers are currently exploiting two critical Cisco SD‑WAN Manager CVEs, urges users to apply patches before delays, and confirms active exploitation in the wild.

    02000105
    4.1K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨Cisco Catalyst SD-WANの脆弱性、さらに2件の悪用が明らかに:CVE-2026-20128、CVE-2026-20122 ⚠️米CISA、Apple製品の古い脆弱性3件をKEVカタログに追加(CVE-2023-43000、CVE-2021-30952、CVE-2023-41974) 〜サイバーアラート3月6日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44386/

    Post summary

    The alert reports that two Cisco SD‑WAN CVEs (CVE‑2026‑20128, CVE‑2026‑20122) have confirmed exploitation cases, while also noting the addition of three older Apple product CVEs to the CISA KEV catalog. No PoC, patch, or detailed technical information is provided.

    01010195
    1.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Cisco reports active exploitation of two patched Catalyst SD-WAN flaws (CVE-2026-20128, CVE-2026-20122) following a zero-day tied to UAT-8616. Targeted attacks on network devices continue. #CatalystSDWAN #NetworkSecurity #USA https://ift.tt/gt5TMZo

    Post summary

    Cisco reports that CVE‑2026‑20128 and CVE‑2026‑20122, despite being patched, are still being exploited in targeted attacks against Catalyst SD‑WAN devices.

    00020184
    3.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager (formerly vManage) < 20.18 CISA KEV: Yes — federal deadline passed April 24 (CVE-2026-20133), May 8 (CVE-2026-20128) Exploitation Status: Actively exploited in…

    Post summary

    Four Cisco Catalyst SD-WAN Manager CVEs (CVE‑2026‑20133, ‑20128, ‑20122, ‑20127) are actively exploited in the wild, with CISA KEV deadlines already passed.

    1000075
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-20133: CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager formerly vManage < 20.18 CISA KEV: Yes — federal deadline passed April 24 CVE-2026-20133, May 8 CVE-2026-20128 Exploitation Status: Actively…

    Post summary

    The note lists multiple CVEs affecting Cisco SD‑WAN Manager, identifies them as CISA KEVs, and indicates active exploitation, but provides no PoC, exploit code, or patch information.

    1000078
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2026-20128 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-20, signaling confirmed in-the-wild exploitation and setting a rapid r

    Post summary

    CISA’s addition of CVE-2026-20128 to its KEV catalog confirms it is actively exploited in the wild.

    1000033
    151 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-20128. What happened CISA added CVE-2026-20128 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-20, signaling confirmed in-the-wild exploitation and setting a rapid remediation window for impacted orgs CISA KEV.

    Post summary

    CISA has added CVE‑2026‑20128 to its Known Exploited Vulnerabilities catalog, confirming it is being exploited in the wild and urging rapid remediation.

    1000039
    151 followersView on X
  • キタきつね@foxbook
    General

    CISAが既知の悪用された脆弱性8件をカタログに追加 CISA Adds Eight Known Exploited Vulnerabilities to Catalog #CISA (Apr 20) CVE-2023-27351 PaperCut NG/MF 認証エラーの脆弱性 CVE-2024-27199 JetBrains TeamCity 相対パストラバーサル脆弱性 CVE-2025-2749 Kentico Xperienceのパストラバーサル脆弱性 CVE-2025-32975 Quest KACEシステム管理アプライアンス(SMA)の認証エラーの脆弱性 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) のクロスサイトスクリプティング脆弱性 CVE-2026-20122 Cisco Catalyst SD-WAN Managerにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-20128 Cisco Catalyst SD-WAN Managerにおける、パスワードを回復可能な形式で保存する脆弱性 CVE-2026-20133 Cisco Catalyst SD-WAN Managerにおける機密情報が不正アクセス者に漏洩する脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog

    Post summary

    CISA updates its catalog with eight CVEs identified as "known exploited," listing basic vulnerability types, but provides no technical depth, PoC, or mitigation details.

    00010559
    4.8K followersView on X
  • kokumօtօ@__kokumoto
    General

    CVE-2023-27351 PaperCut NG/MF CVE-2024-27199 JetBrains TeamCity CVE-2025-2749 Kentico Xperience CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) CVE-2025-48700 Zimbra Collaboration Suite (ZCS) CVE-2026-20122/CVE-2026-20128/CVE-2026-20133 Cisco Catalyst SD-WAN Manager

    Post summary

    The content is a simple list of CVE identifiers for various products, with no additional context or actionable details.

    10000812
    7.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.6--

Explore more