North America
Cisco
Cisco has warned users about two vulnerabilities in Catalyst SD-WAN Manager (formerly known as SD-WAN vManage) that are currently under active exploitation in the wild.
The vulnerabilities disclosed are:
- CVE-2026-20122 (CVSS score: 7.1) – An arbitrary file overwrite vulnerability that could allow an authenticated remote attacker to overwrite arbitrary files on the local file system. Successful exploitation requires valid read-only credentials with API access on the affected system.
- CVE-2026-20128 (CVSS score: 5.5) – An information disclosure vulnerability that could allow an authenticated local attacker to gain Data Collection Agent (DCA) user privileges on the affected system. Successful exploitation requires valid vManage credentials.
The company did not provide details about the scale of the attacks or the threat actors involved. The disclosure comes a week after Cisco reported that a critical vulnerability in Cisco Catalyst SD-WAN Controller and Catalyst SD-WAN Manager, tracked as CVE-2026-20127 with a CVSS score of 10.0, was exploited by a sophisticated threat actor known as UAT-8616 to establish persistent access to high-value organizations.
How it could affect your business
Since these vulnerabilities are already being actively exploited, users should update to a fixed software release as soon as possible. Organizations should also restrict access from unsecured networks, place appliances behind a firewall, disable HTTP access for the Catalyst SD-WAN Manager administrator portal and turn off services such as HTTP and FTP when not required. Changing default administrator passwords and closely monitoring system logs for unexpected inbound or outbound traffic can also help detect suspicious activity early.
