LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-34026: Versa Concerto Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 22, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-34026 to its Known Exploited Vulnerabilities catalog on Jan 22, 2026, with a federal patch deadline of Feb 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The…

Versa Concerto contains an improper authentication vulnerability in its Traefik reverse proxy configuration. Attackers can reach administrative endpoints and retrieve heap dumps and trace logs through the internal Actuator endpoint.

This matters because the product is an SD-WAN orchestration platform; unauthorized access to these endpoints can expose internal operational data without requiring valid credentials.

How it works

The weakness is categorized as CWE-288, an authentication bypass that occurs when an alternate path or channel is not properly protected. In this case the Traefik reverse proxy configuration permits direct access to administrative endpoints that should be restricted. An attacker who reaches the internal Actuator endpoint can obtain heap dumps and trace logs that contain sensitive runtime information.

Am I affected? How to find it in your systems

Inventory all deployments of the Versa Concerto SD-WAN orchestration platform. Examine the Traefik reverse proxy configuration and confirm whether the Actuator endpoint is reachable from untrusted networks. Review access controls around administrative paths and inspect logs for unexpected requests to Actuator-related URIs. Exact version and configuration details must be confirmed against the vendor advisory.

How to remediate

Apply mitigations per the vendor instructions. Follow applicable BOD 22-01 guidance for cloud services. If mitigations cannot be implemented, discontinue use of the product.

If you can't patch immediately

Segment the orchestration platform so that only trusted management networks can reach administrative endpoints. Apply network-level controls to block external access to the Actuator endpoint. Monitor logs for anomalous requests to administrative paths and maintain visibility into cloud-service activity as required by BOD 22-01.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVersa · Concerto
WeaknessCWE-288
Added to CISA KEVJan 22, 2026
Federal patch deadlineFeb 12, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities