Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

The Offspring’s Dexter Holland joins Electric Callboy on new single

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Cisco confirms active exploitation of two vulnerabilities in Catalyst SD-WAN Manager
Celebrities

Cisco confirms active exploitation of two vulnerabilities in Catalyst SD-WAN Manager

By March 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 5, 2026Vulnerabilities / Enterprise Security

SD-WAN Manager Vulnerabilities

Cisco has revealed that two more vulnerabilities affecting Catalyst SD-WAN Manager (formerly known as SD-WAN vManage) are being exploited in the wild.

The vulnerabilities in question are as follows.

CVE-2026-20122 (CVSS Score: 7.1) – Arbitrary file overwrite vulnerability could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. For successful exploitation, the attacker must have valid read-only credentials with API access on the affected system. CVE-2026-20128 (CVSS Score: 5.5) – Information disclosure vulnerability could allow an authenticated, local attacker to gain Data Collection Agent (DCA) user privileges on an affected system. Successful exploitation requires the attacker to have valid vManage credentials on the affected system.

Patches for security flaws in addition to CVE-2026-20126, CVE-2026-20129, and CVE-2026-20133 were released by Cisco late last month in the following versions:

Versions prior to 20.91 – Migrate to fix release. Version 20.9 – Fixed in 20.9.8.2 Version 20.11 – Fixed in 20.12.6.1 Version 20.12 – Fixed in 20.12.5.3 and 20.12.6.1 Version 20.13 – Fixed in 20.15.4.2 Version 20.14 – Fixed in 20.15.4.2 Version 20.15 – Fixed in 20.15.4.2 Version 20.16 – Fixed in 20.18.2.1 Version 20.18 – Fixed in 20.18.2.1

“In March 2026, Cisco PSIRT became aware of active exploitation of the vulnerabilities listed exclusively in CVE-2026-20128 and CVE-2026-20122,” the network equipment giant said. The company did not elaborate on the scale of the operation or who was behind it.

Given the active exploitation, we recommend that users take steps to update to fixed software releases as soon as possible, restrict access from unsecured networks, secure the appliance behind a firewall, disable HTTP in the Catalyst SD-WAN Manager Web UI admin portal, turn off network services such as HTTP and FTP when not needed, change the default administrator password, and monitor log traffic for unexpected traffic to and from the system.

This disclosure comes one week after the company announced that a critical security flaw (CVE-2026-20127, CVSS score: 10.0) in Cisco Catalyst SD-WAN Controllers and Catalyst SD-WAN Manager was exploited by sophisticated cyber attackers, tracked as UAT-8616, to establish a persistent foothold in high-value organizations.

This week, Cisco also released updates that address two maximum severity security vulnerabilities (CVE-2026-20079 and CVE-2026-20131, CVSS score: 10.0) in Secure Firewall Management Center. This vulnerability could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary Java code as root on an affected device.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticlePost-Quantum Cryptography Webinar for Security Leaders
Next Article Netflix acquires Ben Affleck’s AI film production company InterPositive

Related Posts

Princess Charlene of Monaco is enthusiastic about Monaco F1 Grand Prix

June 5, 2026

Queen Camilla wears Queen Elizabeth’s Diamond Star Brooch

June 5, 2026

Emily Blunt wears custom Stella McCartney to Disclosure Day in London

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Offspring’s Dexter Holland joins Electric Callboy on new single

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Top 10 Pop, Rock, and Country Concerts of the Summer – Plus Jazz and Classical

Trending Posts

The Offspring’s Dexter Holland joins Electric Callboy on new single

June 6, 2026

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

June 6, 2026

Black Crowes’ Chris Robinson makes comments on stage

June 6, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.