Thursday, October 8, 2026

Cisco Catalyst SD-WAN Flaws Expose Devices to Root Access, Threatening Network Security

Cisco has issued critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.

The advisory (cisco-sa-sdwan-authbp-qwCX8D4v), originally published on February 25, 2026, was urgently updated on March 5, 2026, after Cisco confirmed active in-the-wild exploitation of two specific flaws.​

Vulnerability Analysis and Active Exploitation

Discovered during internal security testing by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG), the flaws span authentication bypass, privilege escalation, and information disclosure mechanisms.

The most severe flaw, CVE-2026-20129, holds a critical CVSS base score of 9.8 and allows remote, unauthenticated attackers to obtain netadmin privileges via improperly authenticated API requests.

Meanwhile, CVE-2026-20126 allows a low-privileged local attacker to achieve complete root access on the underlying operating system by exploiting an insufficient REST API authentication mechanism.

In early March 2026, Cisco updated the advisory to warn about active exploitation of CVE-2026-20122 and CVE-2026-20128.

Exploitation of CVE-2026-20122 allows authenticated threat actors to overwrite arbitrary files on the local file system and gain vmanage user privileges, posing a direct threat to system integrity.​

CVE IDCVSS ScoreSeverityDescriptionCWE
CVE-2026-20129 â€‹9.8 â€‹Critical â€‹API Authentication Bypass (netadmin access) â€‹CWE-287 â€‹
CVE-2026-20126 â€‹7.8 â€‹High â€‹Local Privilege Escalation (Root access) â€‹CWE-257 â€‹
CVE-2026-20133 â€‹7.5 â€‹High â€‹Unauthenticated Remote Information Disclosure â€‹CWE-200 â€‹
CVE-2026-20122 â€‹7.1 â€‹High â€‹Arbitrary File Overwrite (vmanage access) â€‹N/A
CVE-2026-20128 â€‹5.5 â€‹Medium â€‹DCA Credential Information Disclosure â€‹N/A

Remediation and Affected Versions

The vulnerabilities affect Cisco Catalyst SD-WAN Manager regardless of the underlying device configuration.

Notably, releases 20.18 and later remain unaffected by CVE-2026-20129 and CVE-2026-20128. T

here are currently no workarounds available for any of these vulnerabilities, making immediate software upgrades mandatory to secure enterprise SD-WAN fabrics.

Cisco recommends disabling HTTP for the administrator portal and restricting internet access to the system by placing components behind two-layer firewalls.

Mitigation CategoryKey ActionsSource
Fixed Software ReleasesUpgrade to versions 20.9.8.2, 20.12.6.1, 20.15.4.2, or 20.18.2.1 depending on current branch â€‹.Cisco PSIRT â€‹
Network HardeningRestrict access to known, trusted hosts; deploy SD-WAN components behind firewalls â€‹.Cisco PSIRT â€‹
Service ConfigurationDisable HTTP for web UI administrator portal; disable unnecessary services like FTP â€‹.Cisco PSIRT â€‹
MonitoringRoute logs to an external server and monitor traffic for anomalous activity indicating exploitation â€‹.Cisco PSIRT ​

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR:...

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489,...

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to...

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to...

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational...

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five...

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related...

Related Articles

Recent News