Cisco has issued critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.
The advisory (cisco-sa-sdwan-authbp-qwCX8D4v), originally published on February 25, 2026, was urgently updated on March 5, 2026, after Cisco confirmed active in-the-wild exploitation of two specific flaws.​
Vulnerability Analysis and Active Exploitation
Discovered during internal security testing by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG), the flaws span authentication bypass, privilege escalation, and information disclosure mechanisms.
The most severe flaw, CVE-2026-20129, holds a critical CVSS base score of 9.8 and allows remote, unauthenticated attackers to obtain netadmin privileges via improperly authenticated API requests.
Meanwhile, CVE-2026-20126 allows a low-privileged local attacker to achieve complete root access on the underlying operating system by exploiting an insufficient REST API authentication mechanism.
In early March 2026, Cisco updated the advisory to warn about active exploitation of CVE-2026-20122 and CVE-2026-20128.
Exploitation of CVE-2026-20122 allows authenticated threat actors to overwrite arbitrary files on the local file system and gain vmanage user privileges, posing a direct threat to system integrity.​
Remediation and Affected Versions
The vulnerabilities affect Cisco Catalyst SD-WAN Manager regardless of the underlying device configuration.
Notably, releases 20.18 and later remain unaffected by CVE-2026-20129 and CVE-2026-20128. T
here are currently no workarounds available for any of these vulnerabilities, making immediate software upgrades mandatory to secure enterprise SD-WAN fabrics.
Cisco recommends disabling HTTP for the administrator portal and restricting internet access to the system by placing components behind two-layer firewalls.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





