cbcvebase.
CVE-2026-20122
published 2026-02-25

CVE-2026-20122: A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file…

PriorityP184medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-04-23
Exploited in the wild
EPSS
7.02%
93.4th percentile
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Affected

341 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan
ciscocatalyst_sd-wan_manager< 20.9.8.220.9.8.2
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.10 < 20.12.5.320.12.5.3
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.220.15.4.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.18.2.120.18.2.1
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager

Detection & IOCsextracted from sources · hover to see the quote

ip38.181.52[.]89
ip89.125.244[.]33
ip89.125.244[.]51
ip38.60.214[.]92
ip65.20.67[.]134
ip104.233.156[.]1
ip194.233.100[.]40
port7443
port31337
otherfece5b954e69b2c6a8d0a1029631a0d7
path/api/v1/handshake
path/api/v1/results
path/api/v1/payloads
path/api/v1/exfiltrate
path/api/v1/tasks
path/api/v1/init
  • The Behinder webshell variant deployed in Cluster 2 uses only Base64 encoding (not AES), which differs from typical Behinder variants — detection rules should account for this encoding deviation.
  • Monitor SD-WAN Manager systems for unauthorized SSH key additions, NETCONF configuration modifications, and privilege escalation attempts to root — these are post-compromise TTPs observed from UAT-8616.
  • Cluster 10 targets credential theft: hunt for attempts to read admin user hashdumps, JSON Web Token (JWT) key chunks used for REST API authentication, and AWS credentials for vManage on compromised systems.
  • IP 83.229.126[.]195 (Hong Kong) is both an XMRig miner download source and a known Cobalt Strike C2 — block and alert on connections to this IP.
  • ·CVE-2026-20122 (arbitrary file overwrite) requires the attacker to have valid read-only credentials with API access — unauthenticated exploitation is not possible for this CVE alone; it must be chained with other vulnerabilities (CVE-2026-20133, CVE-2026-20128) for unauthenticated access.
  • ·These vulnerabilities affect Cisco Catalyst SD-WAN Manager software regardless of device configuration — there are no configuration-based mitigations; patching is the only remediation.
  • ·There are no workarounds that address these vulnerabilities — customers must upgrade to the fixed software release.

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.