← All Advisories

CVE-2026-20122: Cisco Catalyst SD-WAN Manager

Status: KEV  |  Advisory ID: CVE-2026-20122

Key Details

CVECVE-2026-20122
Affected productsCisco Catalyst SD-WAN Manger
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-648 (Incorrect Use of Privileged APIs)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-20.
Exploitation prediction (EPSS)25% probability of exploitation in the next 30 days (98% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-04-23 (CISA KEV, Binding Operational Directive).

What to Know

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20122