• News/
  • https://www.bleepingcomputer.com/news/security/cisco-flags-more-sd-wan-flaws-as-actively-exploited-in-attacks/

Cisco flags more SD-WAN flaws as actively exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 5, 2026
·
Updated

​Cisco has flagged two Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices. Catalyst SD-WAN Manager (formerly vManage) is network management software that enables admins to monitor and manage up to 6,000 Catalyst SD-WAN devices from a single centralized dashboard. "In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only," the company warned in an update to a February 25 advisory. "The vulnerabilities that are described in the other CVEs in this advisory are not known to have been compromised. Cisco strongly recommends that customers upgrade to a fixed software release to remediate these vulnerabilities." The high-severity arbitrary file overwrite vulnerability (CVE-2026-20122) can only be exploited by remote attackers with valid read-only credentials with API access, while the medium-severity information disclosure flaw (CVE-2026-20128) requires local attackers to have valid vmanage credentials on the targeted systems. Cisco added that these vulnerabilities affect Catalyst SD-WAN Manager software, regardless of device configuration. Last week, the company also tagged a critical authentication bypass vulnerability (CVE-2026-20127) as exploited in zero-day attacks, enabling highly sophisticated threat actors to compromise controllers and add malicious rogue peers to targeted networks since at least 2023. These ...

Read full article

Affected Software

2 affected components
Cisco Catalyst SD-WAN Manager<6,000
Cisco Secure Firewall Management Center<unpatched
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses two security flaws in Cisco's Catalyst SD-WAN Manager that are being actively exploited in attacks.

2

What security implications are discussed in the article?

The article highlights that these vulnerabilities may allow attackers to compromise network management systems and potentially take control over network environments.

3

What products or software are affected by the vulnerabilities?

The affected products include Cisco Catalyst SD-WAN Manager and Cisco Secure Firewall Management Center.

4

What actions does Cisco recommend for administrators?

Cisco urges administrators to upgrade their vulnerable SD-WAN devices to mitigate the risks associated with these actively exploited flaws.

5

Are there any specific versions mentioned that are vulnerable?

Yes, the article indicates that versions of Cisco Catalyst SD-WAN Manager prior to 6,000 are vulnerable, as well as unpatched versions of Cisco Secure Firewall Management Center.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203