CVE-2026-20122
published 2026-02-25CVE-2026-20122: A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file…
PriorityP184medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-04-23
Exploited in the wild
EPSS
7.02%
93.4th percentile
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Affected
341 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan | — | — |
| cisco | catalyst_sd-wan_manager | < 20.9.8.2 | 20.9.8.2 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.10 < 20.12.5.3 | 20.12.5.3 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.2 | 20.15.4.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18.2.1 | 20.18.2.1 |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The Behinder webshell variant deployed in Cluster 2 uses only Base64 encoding (not AES), which differs from typical Behinder variants — detection rules should account for this encoding deviation. ↗
- →Monitor SD-WAN Manager systems for unauthorized SSH key additions, NETCONF configuration modifications, and privilege escalation attempts to root — these are post-compromise TTPs observed from UAT-8616. ↗
- →Cluster 10 targets credential theft: hunt for attempts to read admin user hashdumps, JSON Web Token (JWT) key chunks used for REST API authentication, and AWS credentials for vManage on compromised systems. ↗
- →IP 83.229.126[.]195 (Hong Kong) is both an XMRig miner download source and a known Cobalt Strike C2 — block and alert on connections to this IP. ↗
- ·CVE-2026-20122 (arbitrary file overwrite) requires the attacker to have valid read-only credentials with API access — unauthenticated exploitation is not possible for this CVE alone; it must be chained with other vulnerabilities (CVE-2026-20133, CVE-2026-20128) for unauthenticated access. ↗
- ·These vulnerabilities affect Cisco Catalyst SD-WAN Manager software regardless of device configuration — there are no configuration-based mitigations; patching is the only remediation. ↗
- ·There are no workarounds that address these vulnerabilities — customers must upgrade to the fixed software release. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Catalyst SD-WAN Manager up to 20.18.2_LI_Images incorrect privileged apis (cisco-sa-sdwan-authbp-qwCX8D4v / Nessus ID 299999)
vuldb·2026-04-21·CVSS 5.4
CVE-2026-20122 [MEDIUM] Cisco Catalyst SD-WAN Manager up to 20.18.2_LI_Images incorrect privileged apis (cisco-sa-sdwan-authbp-qwCX8D4v / Nessus ID 299999)
A vulnerability was found in Cisco Catalyst SD-WAN Manager. It has been classified as critical. This impacts an unknown function. The manipulation leads to incorrect use of privileged apis.
This vulnerability is uniquely identified as CVE-2026-20122. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
GHSA
GHSA-9qpv-49q8-9chx: A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local fi
ghsa_unreviewed·2026-02-25
CVE-2026-20122 [MEDIUM] CWE-648 GHSA-9qpv-49q8-9chx: A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local fi
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
VulnCheck
Cisco catalyst_sd-wan_manager Incorrect Use of Privileged APIs
vulncheck·2026·CVSS 5.4
CVE-2026-20122 [MEDIUM] Cisco catalyst_sd-wan_manager Incorrect Use of Privileged APIs
Cisco catalyst_sd-wan_manager Incorrect Use of Privileged APIs
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Affected: Cisco catalyst_sd-wan_manager
Required Action: Apply remediations or mitigations per vendor instructions or dis
CISA
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
cisa·2026-04-20·CVSS 5.4
CVE-2026-20122 [MEDIUM] CWE-648 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Vulnerability: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Affected: Cisco Catalyst SD-WAN Manger
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL
Cisco
Cisco Catalyst SD-WAN Vulnerabilities
vendor_cisco·2026-02-26·CVSS 9.8
CVE-2026-20122 [CRITICAL] CWE-200 Cisco Catalyst SD-WAN Vulnerabilities
Cisco Catalyst SD-WAN Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
Cisco
Cisco Catalyst SD-WAN Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20122 Cisco Catalyst SD-WAN Vulnerabilities
CVE-2026-20122: Cisco Catalyst SD-WAN Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-200, CWE-257, CWE-287, CWE-200, CWE-257, CWE-287, CWE-648, CWE-200, CWE-257, CWE-287, CWE-200, CWE-257, CWE-287, CWE-648
Bug IDs: CSCws33583, CSCws33584, CSCws33585, CSCws33583, CSCws33584
No detection rules found.
No public exploits indexed.
Hackernews
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
blogs_hackernews·2026-06-16·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-20262 , carries a CVSS score of 6.5 out of 10.0.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in an advisory.
The issue, the networking equipment company added, stems from inadequat
Bleepingcomputer
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
blogs_bleepingcomputer·2026-06-15·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
## Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
## Sergiu Gatlan
Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges.
Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard.
The now-patched zero-day security flaw affects all deployment types, regardless of device configuration, including on-prem deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
Cisco said the issue stems from insufficient validation of user-supplied input during file uploads, which can allow low-privilege remote attackers
Hackernews
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
blogs_hackernews·2026-06-06·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245 , carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary co
Bleepingcomputer
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
blogs_bleepingcomputer·2026-06-05·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Sergiu Gatlan
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245 ) actively exploited in attacks enabling root privilege escalation.
The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root.
"An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the atta
Hackernews
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
blogs_hackernews·2026-05-15·CVSS 5.4
CVE-2026-20182 [MEDIUM] CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026.
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182 . It's rated 10.0 on the CVSS scoring system, indicating maximum severity.
"Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass vulnerability
Tenable
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
blogs_tenable·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2
Talos
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
blogs_talos·2026-05-14·CVSS 5.4
CVE-2026-20182 [MEDIUM] Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
## Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Cisco Talos is tracking the active exploitation of CVE-2026-20182 , an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.
Successful exploitation of CVE-2026-20182 allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
The exploitation of CVE-2026-20182 appears to have been limited so far and Talos clusters this activity under UAT-8616 with high confidence.
Talos is also aware of a series of threat actors, distinct from UAT-8616, that have been observed to be exploiting a different, previously disclosed set of vulnerabilities, in a new way than p
Hackernews
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
blogs_hackernews·2026-04-21·CVSS 7.5
CVE-2023-27351 [HIGH] CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation.
The list of vulnerabilities is as follows -
CVE-2023-27351 (CVSS score: 8.2) - An improper authentication vulnerability in PaperCut NG/MF that could allow an attacker to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2024-27199 (CVSS score: 7.3) -
Bleepingcomputer
CISA flags new SD-WAN flaw as actively exploited in attacks
blogs_bleepingcomputer·2026-04-21·CVSS 5.4
CVE-2026-20133 [MEDIUM] CISA flags new SD-WAN flaw as actively exploited in attacks
## CISA flags new SD-WAN flaw as actively exploited in attacks
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks.
Catalyst SD-WAN Manager (formerly known as vManage) is a network management software that helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
Cisco patched this information disclosure vulnerability ( CVE-2026-20133 ) in late February, saying that it allows unauthenticated remote attackers to access sensitive information on unpatched devices.
"This vulnerability is due to insufficient file system access restrictions. An attacker could exploit
Bleepingcomputer
Cisco flags more SD-WAN flaws as actively exploited in attacks
blogs_bleepingcomputer·2026-03-05·CVSS 5.4
[MEDIUM] Cisco flags more SD-WAN flaws as actively exploited in attacks
## Cisco flags more SD-WAN flaws as actively exploited in attacks
## Sergiu Gatlan
Cisco has flagged two Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices.
Catalyst SD-WAN Manager (formerly vManage) is network management software that enables admins to monitor and manage up to 6,000 Catalyst SD-WAN devices from a single centralized dashboard.
"In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only," the company warned in an update to a February 25 advisory.
"The vulnerabilities that are described in the other CVEs in this advisory are not known to have been compromised. Cisco strongly recommends that customers upgr
Tenable
CVE-2026-20127 Zero-Day Auth Bypass Exploited
blogs_tenable·2026-02-25·CVSS 5.4
CVE-2026-20128 [MEDIUM] CVE-2026-20127 Zero-Day Auth Bypass Exploited
March 5: This blog has been updated to include a reference to CVE-2026-20128 and CVE-2026-20122, two additional SD-WAN Manager vulnerabilities that Cisco has confirmed have been exploited in the wild.
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Wiz
CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20122 [MEDIUM] CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20122 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Source : NVD
## 5.4
Score
Published February 25, 2026
Severity MEDIUM
CNA Score 5.4
Affe
2026-02-25
Published
2026-04-20
Added to CISA KEV
Exploited in the wild