Back to Feed
Zero-dayMar 5, 2026

Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

Cisco has confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager, with CVE-2026-20122 being an arbitrary file overwrite flaw (CVSS 7.1) that allows authenticated remote attackers to overwrite files on the local file system. The vulnerabilities are actively being exploited in the wild.

Summary

Cisco has confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager, with CVE-2026-20122 being an arbitrary file overwrite flaw (CVSS 7.1) that allows authenticated remote attackers to overwrite files on the local file system. The vulnerabilities are actively being exploited in the wild.

Indicators of Compromise

  • cve — CVE-2026-20122