Just when network admins thought the Cisco SD-WAN patch queue might finally be shrinking, Switchzilla has confirmed miscreants are exploiting more vulnerabilities in its SD-WAN management software. The newly abused flaws affect Cisco Catalyst SD-WAN Manager, the platform formerly known as vManage that sits at the center of many organizations' SD-WAN deployments. One of the bugs, CVE-2026-20122, carries a CVSS score of 7.1 and allows an authenticated remote attacker to overwrite arbitrary files on the local filesystem. The second issue, CVE-2026-20128, is a lower-rated information disclosure flaw with a CVSS score of 5.5 that could allow an authenticated local attacker to gain Data Collection Agent (DCA) user privileges on an affected system. In an advisory published this week, Cisco confirmed that attackers are already abusing the flaws: "In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only." As usual with these sorts of notices, Cisco offered little detail about how the flaws are being exploited or who is behind the attacks. The company also declined to say whether the activity is linked to a cyberbaddie it warned about just days earlier. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate these vulnerabilities," the company added. The warning comes barely a week after governments from the Five Eyes intelligence alliance warned that attacke...
Cisco warns of two more SD-WAN bugs under active attack
The Register
·Carly Page
·Published Mar 6, 2026
·Updated
Affected Software
4 affected components
Cisco Catalyst SD-WAN Manager<2026-20122
Cisco Catalyst SD-WAN Controller<2026-20127
Cisco Catalyst SD-WAN Management Software
Cisco Catalyst SD-WAN
Frequently Asked Questions
1
What is the main focus of the security news article?
The article discusses two newly discovered vulnerabilities in Cisco's SD-WAN management software that are currently being exploited by attackers.
2
What vulnerabilities are highlighted in the article?
The article highlights flaws in the Cisco Catalyst SD-WAN Manager and Controller that are under active exploitation.
3
Who is affected by these Cisco SD-WAN vulnerabilities?
Network administrators using Cisco's Catalyst SD-WAN Manager and Controller software are directly affected by these vulnerabilities.
4
What are the potential security risks mentioned in the article?
The security risks include unauthorized access and potential disruption of network services due to the exploitation of the vulnerabilities.
5
What actions does Cisco recommend to mitigate these vulnerabilities?
Cisco recommends patching the affected SD-WAN management software with the latest updates to mitigate the vulnerabilities.