CVE-2022-20775
published 2022-09-30CVE-2022-20775: A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to…
PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-02-27
Exploited in the wild
EPSS
12.47%
95.7th percentile
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Affected
477 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | < 20.6.3 | 20.6.3 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.7 < 20.7.2 | 20.7.2 |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
| cisco | cisco_catalyst_sd-wan | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
65938
snort↗
65958
- →Monitor SD-WAN logs for unexpected software version downgrades followed by reboots, which may indicate CVE-2022-20775 exploitation to gain root access before restoring the original version. ↗
- →Alert on the log message 'Software upgrade not confirmed. Reverting to previous software version' as a potential indicator of deliberate version downgrade for privilege escalation. ↗
- →Detect interactive root login events via the system notification log pattern: system-login-change severity-level:minor user-name:"root". ↗
- →Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown IP addresses as an indicator of unauthorized SSH access. ↗
- →Check for abnormally small (0/1/2 byte) or absent log files in /var/log/ (syslog, wtmp, lastlog, cli-history, bash_history) as evidence of post-exploitation log tampering. ↗
- →Investigate control-connection-state-change log events for unexpected peer-type:vmanage entries, validating peer-system-ip and public-ip against known authorized infrastructure. ↗
- →Look for presence of a cli-history file for a user that has no corresponding bash_history, which may indicate malicious account creation and cleanup activity. ↗
- →Analyze /var/volatile/log/vdebug, /var/log/tmplog/vdebug, and /var/volatile/log/sw_script_synccdb.log specifically for forensic evidence of CVE-2022-20775 exploitation. ↗
- ·CVE-2022-20775 was exploited in the wild as part of a chained attack: threat actor first used CVE-2026-20127 to gain initial access, then downgraded software to exploit CVE-2022-20775 for root escalation, then restored the original version — making the downgrade/restore cycle itself a key detection signal rather than the vulnerability alone. ↗
- ·If a root account was compromised via CVE-2022-20775, Cisco and CISA advise deploying fresh installs rather than attempting to clean existing infrastructure, as persistence mechanisms may survive remediation. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x65r-rvgh-v43v: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges
ghsa_unreviewed·2022-10-01
CVE-2022-20775 [HIGH] CWE-22 GHSA-x65r-rvgh-v43v: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
VulnCheck
Cisco SD-WAN Path Traversal Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-20775 [HIGH] CWE-25 Cisco SD-WAN Path Traversal Vulnerability
Cisco SD-WAN Path Traversal Vulnerability
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Affected: Cisco SD-WAN
Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Exploita
CISA
Cisco SD-WAN Path Traversal Vulnerability
cisa·2026-02-25·CVSS 7.8
CVE-2022-20775 [HIGH] CWE-25 Cisco SD-WAN Path Traversal Vulnerability
Vulnerability: Cisco SD-WAN Path Traversal Vulnerability
Affected: Cisco SD-WAN
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not availa
Cisco
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
vendor_cisco·2022-09-28·CVSS 7.8
CVE-2022-20775 [HIGH] CWE-25 Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Cisco
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20775 Cisco SD-WAN Software Privilege Escalation Vulnerabilities
CVE-2022-20775: Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-25, CWE-282, CWE-25, CWE-282
Bug IDs: CSCwa52793, CSCwb54198
No detection rules found.
No public exploits indexed.
Hackernews
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
blogs_hackernews·2026-06-16·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-20262 , carries a CVSS score of 6.5 out of 10.0.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in an advisory.
The issue, the networking equipment company added, stems from inadequat
Hackernews
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
blogs_hackernews·2026-06-06·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245 , carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary co
Tenable
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
blogs_tenable·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·2026-03-12·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
## February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026 . All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
APT28 exploits MSHTML fl
Checkpoint
2nd March – Threat Intelligence Report
blogs_checkpoint·2026-03-02
CVE-2025-59536 2nd March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate the stolen dataset includes HR-related information, including contact details and employment records f
Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
blogs_talos·2026-02-25·CVSS 7.8
CVE-2026-20127 [HIGH] Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
Cisco Talos is tracking the active exploitation of CVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on the affected system by sending a crafted request to an affected system. Successful exploitation may allow the attacker to gain administrative privileges on the Controller as an internal, high privileged, non-root, user account.
Talos clusters this exploitation and subsequent post-compromise activity as “UAT-8616” whom we assess with high confidence is a highly sophisticated cyber threat actor. After the discovery of active exploitation of the 0-day in the wild, we were able to find evidence that the malicious activity went back at least three y
Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
blogs_talos·2026-02-25·CVSS 7.8
CVE-2026-20127 [HIGH] Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
## Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
Cisco Talos is tracking the active exploitation of CVE-2026-20127 , a vulnerability in Cisco Catalyst SD-WAN Controller, formerly vSmart, that allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on the affected system by sending a crafted request to an affected system. Successful exploitation may allow the attacker to gain administrative privileges on the Controller as an internal, high privileged, non-root, user account.
Talos clusters this exploitation and subsequent post-compromise activity as “UAT-8616” whom we assess with high confidence is a highly sophisticated cyber threat actor. After the discovery of active exploitation of the 0-day in the wild, we were able to find e
Bleepingcomputer
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
blogs_bleepingcomputer·2026-02-25·CVSS 10.0
CVE-2026-20127 [CRITICAL] Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
## Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
## Lawrence Abrams
Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks.
CVE-2026-20127 has a maximum severity of 10.0 and impacts Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) in on-prem and SD-WAN Cloud installations.
Cisco credited the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) for reporting the vulnerability.
In an advisory published today, Cisco said the issue stems from a peering authentication mechanis
Threat Intel
UAT-8616
threat_intel·CVSS 7.8
CVE-2026-20127 [HIGH] UAT-8616
# Threat Actor: UAT-8616
## Description
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
# February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026. All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
- Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
- Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
- APT28 exploits MSHTML
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://github.com/orangecertcc/security-research/security/advisories/GHSA-wmjv-552v-pxjchttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://github.com/orangecertcc/security-research/security/advisories/GHSA-wmjv-552v-pxjchttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdFhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20775
2022-09-30
Published
2026-02-25
Added to CISA KEV
Exploited in the wild