Sunday, September 13, 2026

Cisco Catalyst SD-WAN Flaws Expose Devices to Root Access, Threatening Network Security

Cisco has issued critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.

The advisory (cisco-sa-sdwan-authbp-qwCX8D4v), originally published on February 25, 2026, was urgently updated on March 5, 2026, after Cisco confirmed active in-the-wild exploitation of two specific flaws.​

Vulnerability Analysis and Active Exploitation

Discovered during internal security testing by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG), the flaws span authentication bypass, privilege escalation, and information disclosure mechanisms.

The most severe flaw, CVE-2026-20129, holds a critical CVSS base score of 9.8 and allows remote, unauthenticated attackers to obtain netadmin privileges via improperly authenticated API requests.

Meanwhile, CVE-2026-20126 allows a low-privileged local attacker to achieve complete root access on the underlying operating system by exploiting an insufficient REST API authentication mechanism.

In early March 2026, Cisco updated the advisory to warn about active exploitation of CVE-2026-20122 and CVE-2026-20128.

Exploitation of CVE-2026-20122 allows authenticated threat actors to overwrite arbitrary files on the local file system and gain vmanage user privileges, posing a direct threat to system integrity.​

CVE IDCVSS ScoreSeverityDescriptionCWE
CVE-2026-20129 â€‹9.8 â€‹Critical â€‹API Authentication Bypass (netadmin access) â€‹CWE-287 â€‹
CVE-2026-20126 â€‹7.8 â€‹High â€‹Local Privilege Escalation (Root access) â€‹CWE-257 â€‹
CVE-2026-20133 â€‹7.5 â€‹High â€‹Unauthenticated Remote Information Disclosure â€‹CWE-200 â€‹
CVE-2026-20122 â€‹7.1 â€‹High â€‹Arbitrary File Overwrite (vmanage access) â€‹N/A
CVE-2026-20128 â€‹5.5 â€‹Medium â€‹DCA Credential Information Disclosure â€‹N/A

Remediation and Affected Versions

The vulnerabilities affect Cisco Catalyst SD-WAN Manager regardless of the underlying device configuration.

Notably, releases 20.18 and later remain unaffected by CVE-2026-20129 and CVE-2026-20128. T

here are currently no workarounds available for any of these vulnerabilities, making immediate software upgrades mandatory to secure enterprise SD-WAN fabrics.

Cisco recommends disabling HTTP for the administrator portal and restricting internet access to the system by placing components behind two-layer firewalls.

Mitigation CategoryKey ActionsSource
Fixed Software ReleasesUpgrade to versions 20.9.8.2, 20.12.6.1, 20.15.4.2, or 20.18.2.1 depending on current branch â€‹.Cisco PSIRT â€‹
Network HardeningRestrict access to known, trusted hosts; deploy SD-WAN components behind firewalls â€‹.Cisco PSIRT â€‹
Service ConfigurationDisable HTTP for web UI administrator portal; disable unnecessary services like FTP â€‹.Cisco PSIRT â€‹
MonitoringRoute logs to an external server and monitor traffic for anomalous activity indicating exploitation â€‹.Cisco PSIRT ​

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News