Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20122 | Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown. Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable. | 5.4 | 25% | KEV |
| large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide | |
| CVE-2026-20127 | Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile). Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product. | 10.0 | 88% | KEV |
| large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise… | |
| CVE-2026-20128 | DCA Password File Disclosure in Cisco Catalyst SD-WAN Manager CVE-2026-20128 is a password-storage flaw (CWE-257, Storing Passwords in a Recoverable Format) in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which leaves a credential file containing the DCA user password on affected systems. An unauthenticated, remote attacker can send a crafted HTTP request to read that file and recover the DCA password. With the recovered credentials, the attacker can access another affected system and gain DCA user privileges, enabling chained compromise across SD-WAN management infrastructure. Organizations running Cisco Catalyst SD-WAN Manager releases earlier than 20.18 are affected; releases 20.18 and later are not. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, with an EPSS 30-day exploitation probability of 6.9% (94th percentile); no public proof-of-concept is known, and CISA has issued Emergency Directive 26-03 and hunt-and-hardening guidance for Cisco SD-WAN devices. Do: Upgrade Cisco Catalyst SD-WAN Manager to release 20.18 or later, which is not affected. In the meantime, follow CISA's Emergency Directive 26-03 and the 'Hunt & Hardening Guidance for Cisco SD-WAN Devices' to assess exposure, hunt for crafted HTTP requests reading the DCA credential file, and rotate DCA credentials on affected systems; if you use affected cloud-service offerings and mitigations are unavailable, follow applicable BOD 22-01 guidance or discontinue use. | 7.5 | 7% | KEV |
| large≈10,000–100,000 SD-WAN Manager deployments worldwide (order of tens of thousands) | |
| CVE-2026-20131 | Unauthenticated Java Deserialization RCE in Cisco FMC and SCC CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization. | 10.0 | 33% | KEV ransomware |
| largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed |
Full article449 words · extracted from helpnetsecurity.com · click to collapse
Cisco has confirmed that two Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128 and CVE-2026-20122) patched in late February 2025 are being exploited by attackers.
The exploited vulnerabilities (CVE-2026-20128, CVE-2026-20122)
CVE-2026-20128 is a bug in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which could allow an authenticated, local attacker to gain DCA user privileges on an affected system.
“To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system,” Cisco explained.
“This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges.”
CVE-2026-20122 affects the solution’s API. If successfully exploited by authenticated, remote attackers, it allows them to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Arthur Vidineyev of the Cisco Advanced Security Initiatives Group has been credited with uncovering these flaws, as well as three additional ones covered by the same advisory.
“Cisco strongly recommends that customers upgrade to a fixed software release to remediate these vulnerabilities,” the company added in the updated advisory.
The company did not share specific details about in-the-wild CVE-2026-20128 and CVE-2026-20122 exploitation, or whether these flaws are being leveraged by the “highly sophisticated” cyber threat actor whose activities were disclosed a week ago.
That threat actor exploited CVE-2026-20127 – a zero-day authentication bypass vulnerability – to “log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account,” and that use that access to “manipulate network configuration for the SD-WAN fabric.”
More fixes for Cisco security solutions
Also today, Cisco fixed 48 vulnerabilities in Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software.
While most of these are medium-severity, two have received a maximum severity score:
- CVE-2026-20079, an authentication bypass flaw in Cisco Secure Firewall Management Center Software, and
- CVE-2026-20131, a remote code execution vulnerability in the same software
The first one can be exploited by sending crafted HTTP requests to an affected device, and the latter by sending a crafted serialized Java object to the web-based management interface of an affected device.
The Dutch National Cyber Security Center said that it expects a public PoC for and large-scale attempts at abuse of these flaws in the short term, and urged admins to upgrade to a fixed version of the software as soon as possible.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/05/cisco-cve-2026-20128-cve-2026-20122-exploited/