CVE-2026-20129Disclosure(cisco / catalyst_sd-wan_manager)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability. 

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-02-25); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-02-25: 3Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-04-22: 1Active Exploitation · 2026-03-05: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 1Technical Details · 2026-04-22: 102-2502-2803-0303-0504-22
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Active Exploitation
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-02-281
Disclosure1
2026-03-031
General1
2026-03-051
Active Exploitation1
2026-04-221
Disclosure1
Full discourse7 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Cisco Catalyst SD-WAN Vulnerabilities CVE-2026-20122/CVE-2026-20126/CVE-2026-20128/CVE-2026-20129/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 『Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、攻撃者が影響を受けるシステムにアクセスし、root権限に昇格し、機密情報にアクセスして任意のファイルを上書きできる可能性があります。』

    Post summary

    Cisco has disclosed multiple SD‑WAN Manager vulnerabilities that could grant attackers root access and file overwrite capabilities; no PoC, exploit code, or evidence of active exploitation is mentioned, and no patch details are provided in the excerpt.

    0301322.3K
    11.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20129 ❗ CVE-2026-20127 ❗ CVE-2026-20126 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-10/ https://t.co/RlhGyfevBO

    Post summary

    The post lists three Cisco CVEs and directs readers to external links for more information, but offers no additional details or actionable content.

    03040326
    6.6K followersView on X
  • FirstPassLab@Felix1325456
    Active Exploitation

    3 Cisco SD-WAN CVEs actively exploited in 8 days. Here's the scorecard: CVE-2026-20127 — CVSS 10.0 — Auth bypass zero-day — Exploited since 2023 CVE-2026-20128 — CVSS 5.5 — DCA credential leak — Exploited (confirmed March 5) CVE-2026-20122 — CVSS 7.1 — File overwrite → privesc — Exploited (confirmed March 5) CVE-2026-20129 — CVSS 9.8 — API auth bypass → netadmin — Not yet CVE-2026-20126 — CVSS 7.8 — REST API → root — Not yet The pattern here is wild: • A CVSS 5.5 "Medium" flaw is being actively exploited while a CVSS 9.8 "Critical" isn't (yet) • That's because attackers chain vulnerabilities — a "medium" credential leak becomes devastating when it enables lateral movement • UAT-8616 exploited CVE-2026-20127 for 3 YEARS before it was discovered • CISA issued Emergency Directive ED 26-03 — that's federal agencies ordered to patch immediately • Google GTIG reported 90 zero-days exploited in 2025, half targeting enterprise infra The lesson: CVSS scores alone don't predict real-world risk. Context and chaining matter more. 5 CVEs. 0 workarounds. Patch is the only path. #CCIE #CiscoSDWAN #NetworkSecurity #Cisco #Networking #CyberSecurity #CISA

    Post summary

    The post reports that three Cisco SD‑WAN CVEs are actively exploited, highlights how lower‑severity flaws can be leveraged via chaining, and stresses that patching is the only remediation path with CISA issuing immediate directives.

    00000136
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20129 A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system a… https://www.cve.org/CVERecord?id=CVE-2026-20129

    Post summary

    A new CVE (CVE-2026-20129) affecting Cisco Catalyst SD-WAN Manager’s API authentication allows unauthenticated remote attackers to gain access to the system.

    00000225
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-20129** pertains to a critical security flaw in the API user authentication mechanism of Cisco Catalyst SD-WAN Manager prior to version 20.18. The vulnerability allows an unauthenticated, remote attacker to send crafted API requests that bypass authentication controls, thereby gaining unauthorized access with **netadmin** privileges. This elevated access enables the attacker to execute commands, potentially leading to full control over the affected system. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #AuthBypass #Apple https://cvetodo.com/cve/CVE-2026-20129

    Post summary

    The post announces a critical authentication bypass in Cisco Catalyst SD‑WAN Manager that lets remote attackers gain netadmin privileges and execute commands.

    0000053
    20 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Cisco Catalyst SD-WAN Manager (CVE-2026-20129) https://vuldb.com/?id.347823

    Post summary

    A severe vulnerability (CVE-2026-20129) in Cisco Catalyst SD-WAN Manager has been disclosed, with a reference to a vulnerability database entry.

    0000094
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-20129 - Critical A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the&... https://www.thehackerwire.com/vulnerability/CVE-2026-20129/ https://t.co/Kz64U6txjz

    Post summary

    A critical vulnerability in Cisco Catalyst SD-WAN Manager’s API authentication permits unauthenticated remote attackers to gain user-level access to affected systems.

    0000064
    115 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.6--

Explore more