にゃん☆たく/takumi.a[verified]@taku888infinityDisclosure
The text announces a set of CVEs affecting Cisco Catalyst SD‑WAN Manager, describing the privilege‑escalation impact but providing no exploit details, PoC, or evidence of active exploitation.
yousukezan[verified]@yousukezanActive Exploitation
The post confirms that CVE‑2026‑20133 is actively exploited, provides a PoC link, and lists vendor patches, underscoring the urgency for remediation.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2026‑20182 and related CVEs in Cisco SD‑WAN are actively exploited by threat actors using webshells, miners, and credential theft tactics, with ZeroZenX Labs PoC releases and Snort SIDs for detection.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
CISA confirms that CVE-2026-20133 is being actively exploited in the wild, but the post contains no exploit code, patch information, or technical vulnerability details.
piyokango[verified]@piyokangoActive Exploitation
The post announces that CISA has added eight known‑exploited vulnerabilities to its catalog, detailing active exploitation evidence, technical impact, and available vendor patches for each CVE.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
TRC analysis confirms that CVE‑2026‑20133 is actively exploited against Cisco SD‑WAN Manager, with attackers accessing data, escalating privileges, and moving laterally, as detailed in the referenced breakdown.
Lyrie.ai[verified]@lyrie_aiDisclosure
CVE-2026-20133 is an insufficient file‑system access issue in SD‑WAN Manager’s web API that permits unauthenticated remote file reads via URL traversal.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The CVEs CVE-2026-20133, CVE-2026-20128, CVE-2026-20122, and CVE-2026-20127 affect Cisco Catalyst SD-WAN Manager (vManage) versions prior to 20.18, with CISA KEV deadlines passed and reports of active exploitation in the wild.