にゃん☆たく/takumi.a[verified]@taku888infinityDisclosure
The advisory announces several CVEs in Cisco Catalyst SD-WAN Manager that could allow attackers to gain root access and overwrite files; no proof of concept or exploitation details are provided.
piyokango[verified]@piyokangoActive Exploitation
The post catalogues several CVEs, some of which have been confirmed as actively exploited by security teams, while also providing mitigation guidance and detailed technical information, but lacks publicly available PoC or exploit code.
The Cyber Security Hub™[verified]@TheCyberSecHubPatch
Cisco alerts stakeholders to exploitation of SD‑WAN Manager via CVE-2026-20128 and CVE-2026-20122, while announcing fixes for 48 additional firewall vulnerabilities.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
Cisco warns that the CVE‑2026‑2256 and CVE‑2026‑20128 flaws in its SD‑WAN Manager are being actively exploited and urges users to take immediate mitigation measures.
Adam[verified]@seoscottsdaleActive Exploitation
The post highlights that CVE‑2026‑20122 and CVE‑2026‑20128 are actively exploited, urging users to apply Cisco’s patch immediately, supported by an official advisory and confirmation from French CERT.
Wasteland[verified]@wastelandweeklyActive Exploitation
The post claims an active zero‑day authentication bypass (CVE‑2026‑20127) in Cisco Catalyst SD‑WAN, with related CVEs confirmed in the wild, and urges immediate patching.
Machina Record[verified]@MachinaRecordActive Exploitation
The alert reports that two Cisco SD‑WAN CVEs (CVE‑2026‑20128, CVE‑2026‑20122) have confirmed exploitation cases, while also noting the addition of three older Apple product CVEs to the CISA KEV catalog. No PoC, patch, or detailed technical information is provided.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
Four Cisco Catalyst SD-WAN Manager CVEs (CVE‑2026‑20133, ‑20128, ‑20122, ‑20127) are actively exploited in the wild, with CISA KEV deadlines already passed.