LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20775: Cisco SD-WAN Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20775 to its Known Exploited Vulnerabilities catalog on Feb 25, 2026, with a federal patch deadline of Feb 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application…

Cisco SD-WAN contains a path traversal vulnerability in its CLI. An authenticated local attacker could exploit improper access controls on CLI commands to execute arbitrary commands as the root user.

This matters for network operators because root-level access on SD-WAN devices can expose routing, policy, and connected infrastructure to further abuse.

How it works

The flaw class combines path traversal (CWE-25) with improper ownership management (CWE-282). An attacker who already holds a local authenticated CLI session supplies crafted command input that bypasses intended access restrictions, allowing the process to reach and execute files outside the expected directory scope with root privileges.

Am I affected? How to find it in your systems

Cisco SD-WAN software operates on WAN edge routers, controllers, and management appliances. Use existing asset-management or network-discovery tools to locate all instances. Examine configurations that permit local or remote CLI access and compare installed software against the vendor advisory for affected releases and settings.

How to remediate

Apply the vendor update named in the advisory. After patching, review CLI command permissions and remove unnecessary local accounts that retain elevated access.

If you can't patch immediately

Follow CISA’s Emergency Directive 26-03 and the associated Hunt & Hardening Guidance for Cisco SD-WAN Devices. Apply BOD 22-01 controls for any cloud-hosted instances or discontinue use of the product if mitigations cannot be implemented.

If your data may have been exposed

Actively exploited vulnerabilities of this type can result in breaches. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · SD-WAN
WeaknessCWE-25
Added to CISA KEVFeb 25, 2026
Federal patch deadlineFeb 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities