CVE-2026-20128

Published Feb 25, 2026

Last updated 3 months ago

CVSS high 7.5
SSH
Network
Zero-day
ICS
Tunneling protocol
OT
Firmware

Overview

Description
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Source
psirt@cisco.com
NVD status
Analyzed
Products
catalyst_sd-wan_manager

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
6
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@cisco.com
CWE-257

Social media

Hype score
Not currently trending
  1. CVE-2026-20133: CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager formerly vManage < 20.18 CISA KEV: Yes — federal deadline passed April 24 CVE-2026-20133, May 8 CVE-2026-20128 Exploitation Status: Actively…

    @lyrie_ai

    14 Jun 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Cisco's Catalyst SD-WAN Manager faces active exploits of CVE-2026-20122 & CVE-2026-20128. Update systems now to protect your network. Link: https://t.co/FptL5AdTds #Cisco #SDWAN #Cybersecurity #Vulnerabilities #Exploitation #Patching #Networks #Security #Threats #CVE #Routers

    @dailytechonx

    7 Jun 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. PoC is now public for CVE-2026-20127 in Cisco Catalyst SD-WAN. UAT-8616 has been exploiting it since 2023, now anyone can try. Two more SD-WAN flaws also active: CVE-2026-20122 and CVE-2026-20128. Patch window is effectively closed. https://t.co/gZOpZQntR2

    @CybrPulse

    7 Mar 2026

    80 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨Cisco Catalyst SD-WANの脆弱性、さらに2件の悪用が明らかに:CVE-2026-20128、CVE-2026-20122 ⚠️米CISA、Apple製品の古い脆弱性3件をKEVカタログに追加(CVE-2023-43000、CVE-2021-30952、CVE-2023-41974) 〜サイバーアラート3月6日

    @MachinaRecord

    6 Mar 2026

    189 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 3 Cisco SD-WAN CVEs actively exploited in 8 days. Here's the scorecard: CVE-2026-20127 — CVSS 10.0 — Auth bypass zero-day — Exploited since 2023 CVE-2026-20128 — CVSS 5.5 — DCA credential leak — Exploited (confirmed March 5) CVE-2026-20122 — CVSS 7.1 — File overw

    @FirstPassLab

    5 Mar 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations