LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20122 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of Apr 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this…

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability that stems from improper file handling on the API interface. An attacker who can reach the interface may upload a malicious file to the local file system, overwrite arbitrary files, and obtain vmanage user privileges on the affected system.

How it works

The weakness is categorized as CWE-648, incorrect use of privileged APIs. The flaw arises because the API interface does not properly validate or restrict file operations performed with elevated privileges. An attacker supplies a crafted file through the API; the system then writes that file to the local file system without sufficient checks, allowing arbitrary overwrites that can elevate the attacker to vmanage user level.

Am I affected? How to find it in your systems

Inventory all deployments of Cisco Catalyst SD-WAN Manager. Confirm the exact software versions and configurations in use against the vendor advisory, because only certain releases and API settings are affected. Review network exposure of the management API, paying particular attention to any interfaces reachable from untrusted networks or lower-privileged accounts.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary fix. After patching, review and restrict API permissions so that file-handling operations are limited to the minimum required privileges. Disable or tightly control any API endpoints that accept file uploads unless they are explicitly required for operations.

If you can't patch immediately

Follow the assessment and mitigation steps in CISA Emergency Directive 26-03 and the associated Hunt & Hardening Guidance for Cisco SD-WAN Devices. Apply network segmentation to isolate SD-WAN Manager instances from untrusted networks. Where cloud services are involved, adhere to the requirements of BOD 22-01; discontinue use of the product if suitable mitigations cannot be implemented. Monitor for indicators of file overwrites or unexpected vmanage sessions until patches can be applied.

If your data may have been exposed

Actively exploited instances of this class of vulnerability have led to unauthorized access and data exposure in other environments. Organizations can run a free exposure scan of their email addresses against known breach data to determine whether their credentials or systems appear in public breach records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Manger
WeaknessCWE-648
Added to CISA KEVApr 20, 2026
Federal patch deadlineApr 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities