Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco Catalyst SD-WAN Flaws Expose Devices to Root Access, Threatening Network Security

Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager. These vulnerabilities could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.

Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager. These vulnerabilities could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.

The advisory, originally published on Thu, Feb 25, 2026, was updated on Thu, Mar 5, 2026, following confirmation of active in-the-wild exploitation of two specific vulnerabilities.

Vulnerability Analysis and Active Exploitation

Discovered by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG), the vulnerabilities include authentication bypass, privilege escalation, and information disclosure mechanisms. The most critical flaw, CVE-2026-20129, has a CVSS base score of 9.8, enabling remote, unauthenticated attackers to obtain netadmin privileges via improperly authenticated API requests.

CVE-2026-20126 allows a low-privileged local attacker to gain root access on the operating system through an insufficient REST API authentication mechanism. Cisco updated the advisory in early March 2026 to address active exploitation of CVE-2026-20122 and CVE-2026-20128. Exploitation of CVE-2026-20122 allows authenticated threat actors to overwrite arbitrary files on the local file system, posing a direct threat to system integrity.

CVE ID CVSS Score Severity Description CWE

CVE-2026-20129 9.8 Critical API Authentication Bypass ( netadmin access) CWE-287

CVE-2026-20126 7.8 High Local Privilege Escalation (Root access) CWE-257

Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager.
Derek Vaughn · Thehackingpost

CVE-2026-20133 7.5 High Unauthenticated Remote Information Disclosure CWE-200

CVE-2026-20122 7.1 High Arbitrary File Overwrite ( vmanage access) N/A

CVE-2026-20128 5.5 Medium DCA Credential Information Disclosure N/A

The vulnerabilities impact Cisco Catalyst SD-WAN Manager regardless of device configuration. Releases 20.18 and later are unaffected by CVE-2026-20129 and CVE-2026-20128. Immediate software upgrades are mandatory as no workarounds are available.

Cisco advises disabling HTTP for the administrator portal and placing components behind two-layer firewalls to restrict internet access.

Advertisement

Mitigation Category Key Actions Source

Fixed Software Releases Upgrade to versions 20.9.8.2, 20.12.6.1, 20.15.4.2, or 20.18.2.1 based on current branch. Cisco PSIRT

Network Hardening Restrict access to known, trusted hosts; deploy SD-WAN components behind firewalls. Cisco PSIRT

Service Configuration Disable HTTP for web UI administrator portal and unnecessary services like FTP. Cisco PSIRT

Monitoring Route logs to an external server and monitor traffic for anomalous activity. Cisco PSIRT

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories