cbcvebase.
CVE-2026-20128
published 2026-02-25

CVE-2026-20128: A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user…

PriorityP183high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-23
Exploited in the wild
EPSS
5.27%
91.6th percentile
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

Affected

142 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan
ciscocatalyst_sd-wan_manager< 20.9.8.220.9.8.2
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.10 < 20.12.5.320.12.5.3
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.220.15.4.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.1820.18
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager

Detection & IOCsextracted from sources · hover to see the quote

ip38.181.52[.]89
ip89.125.244[.]33
ip89.125.244[.]51
ip38.60.214[.]92
ip65.20.67[.]134
ip104.233.156[.]1
ip194.233.100[.]40
port7443
port31337
otherfece5b954e69b2c6a8d0a1029631a0d7
path/api/v1/handshake
path/api/v1/results
path/api/v1/payloads
path/api/v1/exfiltrate
path/api/v1/tasks
path/api/v1/init
  • The Behinder webshell variant deployed in Cluster 2 uses only Base64 encoding instead of the typical AES encryption — detect by absence of AES and presence of Base64-only encoded payloads in JSP webshell traffic.
  • Detect the Nim-based backdoor ('agent1') by monitoring for HTTP beacon traffic to the C2 API paths /api/v1/handshake, /api/v1/results, /api/v1/payloads, /api/v1/exfiltrate, /api/v1/tasks, /api/v1/init.
  • Cluster 10 targets credential theft: monitor for attempts to read admin user hashdumps, JWT key chunks used for REST API authentication, and AWS credentials for vManage.
  • Post-compromise activity includes attempts to add SSH keys, modify NETCONF configurations, and escalate to root privileges — monitor for these actions on SD-WAN Manager and Controller systems.
  • IP 83.229.126[.]195 (Hong Kong) is both an XMRig download source and a known Cobalt Strike C2 — block and alert on connections to this IP.
  • ·CVE-2026-20128 only affects Cisco Catalyst SD-WAN Manager releases prior to 20.18; systems running 20.18 or later are not vulnerable.
  • ·The vulnerability is exploited by sending a crafted HTTP request to read a credential file for the DCA user; the attack vector is the HTTP API surface of the SD-WAN Manager.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.