Zero-dayMar 5, 2026
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
Cisco has confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager, with CVE-2026-20122 being an arbitrary file overwrite flaw (CVSS 7.1) that allows authenticated remote attackers to overwrite files on the local file system. The vulnerabilities are actively being exploited in the wild.
Summary
Cisco has confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager, with CVE-2026-20122 being an arbitrary file overwrite flaw (CVSS 7.1) that allows authenticated remote attackers to overwrite files on the local file system. The vulnerabilities are actively being exploited in the wild.
Indicators of Compromise
- cve — CVE-2026-20122