By Zeljka Zorz
Publication Date: 2026-03-05 13:53:00
Cisco has confirmed that two Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128 and CVE-2026-20122) patched in late February 2025 are being exploited by attackers.
The exploited vulnerabilities (CVE-2026-20128, CVE-2026-20122)
CVE-2026-20128 is a bug in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which could allow an authenticated, local attacker to gain DCA user privileges on an affected system.
“To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system,” Cisco explained.
“This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges.”
CVE-2026-20122 affects the…