Cisco Catalyst SD-WAN Flaws Expose Devices to Root Access, Threatening Network Security
Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager. These vulnerabilities could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.
Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager. These vulnerabilities could allow attackers to bypass authentication, elevate privileges to root, and execute arbitrary commands.
The advisory, originally published on Thu, Feb 25, 2026, was updated on Thu, Mar 5, 2026, following confirmation of active in-the-wild exploitation of two specific vulnerabilities.
Vulnerability Analysis and Active Exploitation
Discovered by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG), the vulnerabilities include authentication bypass, privilege escalation, and information disclosure mechanisms. The most critical flaw, CVE-2026-20129, has a CVSS base score of 9.8, enabling remote, unauthenticated attackers to obtain netadmin privileges via improperly authenticated API requests.
CVE-2026-20126 allows a low-privileged local attacker to gain root access on the operating system through an insufficient REST API authentication mechanism. Cisco updated the advisory in early March 2026 to address active exploitation of CVE-2026-20122 and CVE-2026-20128. Exploitation of CVE-2026-20122 allows authenticated threat actors to overwrite arbitrary files on the local file system, posing a direct threat to system integrity.
CVE ID CVSS Score Severity Description CWE
CVE-2026-20129 9.8 Critical API Authentication Bypass ( netadmin access) CWE-287
CVE-2026-20126 7.8 High Local Privilege Escalation (Root access) CWE-257
Cisco has released critical software updates to address multiple vulnerabilities in the Catalyst SD-WAN Manager.
CVE-2026-20133 7.5 High Unauthenticated Remote Information Disclosure CWE-200
CVE-2026-20122 7.1 High Arbitrary File Overwrite ( vmanage access) N/A
CVE-2026-20128 5.5 Medium DCA Credential Information Disclosure N/A
The vulnerabilities impact Cisco Catalyst SD-WAN Manager regardless of device configuration. Releases 20.18 and later are unaffected by CVE-2026-20129 and CVE-2026-20128. Immediate software upgrades are mandatory as no workarounds are available.
Cisco advises disabling HTTP for the administrator portal and placing components behind two-layer firewalls to restrict internet access.
Mitigation Category Key Actions Source
Fixed Software Releases Upgrade to versions 20.9.8.2, 20.12.6.1, 20.15.4.2, or 20.18.2.1 based on current branch. Cisco PSIRT
Network Hardening Restrict access to known, trusted hosts; deploy SD-WAN components behind firewalls. Cisco PSIRT
Service Configuration Disable HTTP for web UI administrator portal and unnecessary services like FTP. Cisco PSIRT
Monitoring Route logs to an external server and monitor traffic for anomalous activity. Cisco PSIRT
Based on reporting by GBHackers.
