Security News

Cybersecurity news aggregator

πŸ”“
HIGH Vulnerabilities Help Net Security

Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities

Cisco has confirmed active exploitation of CVE-2026-20128 (CVSS 7.5 HIGH), a privilege escalation vulnerability in the Catalyst SD-WAN Manager's Data Collection Agent that requires an attacker to possess valid vManage credentials. Affected versions are Catalyst SD-WAN Manager prior to 20.9.8.2, versions 20.11 to before 20.12.5.3, versions 20.13 to before 20.15.4.2, versions 20.16 to before 20.18, and version 20.12.6 specifically. The fixed versions are 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.
Read Full Article →

Cisco has confirmed that two Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128 and CVE-2026-20122) patched in late February 2025 are being exploited by attackers. The exploited vulnerabilities (CVE-2026-20128, CVE-2026-20122) CVE-2026-20128 is a bug in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which could allow an authenticated, local attacker to gain DCA user privileges on an affected system. β€œTo exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system,” Cisco … More β†’ The post Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities appeared first on Help Net Security .

Share this article