LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20128 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of Apr 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file…

This vulnerability affects Cisco Catalyst SD-WAN Manager and stems from passwords stored in a recoverable format. An authenticated local attacker with low privileges can read a specific credential file on the filesystem and obtain DCA user credentials, resulting in elevated access within the management plane.

How it works

The underlying weakness is CWE-257. The product writes credentials for the DCA user to a file that remains readable by lower-privileged local accounts. An attacker who already holds a local session can simply open or copy that file to retrieve the stored credentials and assume the higher-privileged DCA identity.

Am I affected? How to find it in your systems

Inventory all deployments of Cisco Catalyst SD-WAN Manager in your environment. Confirm the installed version and configuration against the vendor advisory, because only specific builds contain the affected credential file. Review local filesystem permissions and service accounts that run the manager components. Examine authentication and file-access logs for unexpected reads of credential paths by non-DCA users.

How to remediate

Apply the vendor update referenced in the official advisory. After patching, follow CISA’s Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices. Review and tighten local filesystem permissions around credential storage locations. Ensure that only the intended DCA service account can read the file.

If you can't patch immediately

Isolate SD-WAN Manager instances on a dedicated management network segment that restricts inbound access to trusted administrative hosts. Monitor for anomalous local file reads and privilege-escalation attempts. Apply applicable BOD 22-01 controls for any cloud-hosted instances. If compensating measures cannot be implemented, discontinue use of the affected product until remediation is complete.

If your data may have been exposed

Compromises that begin with local credential access can lead to further network intrusion. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether any accounts have already appeared in public listings.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Manager
WeaknessCWE-257
Added to CISA KEVApr 20, 2026
Federal patch deadlineApr 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities