Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities

Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities

Posted on March 5, 2026 By CWS

Cisco has announced that two vulnerabilities in its Catalyst SD-WAN Manager are currently being exploited in the wild. These vulnerabilities, identified as CVE-2026-20122 and CVE-2026-20128, pose significant security risks if left unaddressed.

Details of the Vulnerabilities

The first vulnerability, CVE-2026-20122, carries a CVSS score of 7.1 and involves an arbitrary file overwrite issue. This could potentially enable a remote attacker with valid read-only credentials to overwrite files on the local system. The second vulnerability, CVE-2026-20128, which has a CVSS score of 5.5, could allow an authenticated local attacker to acquire Data Collection Agent user privileges. Both vulnerabilities require the attacker to have specific credentials to exploit successfully.

Patch Releases and Recommendations

To counteract these security threats, Cisco has released patches for the affected software versions. Users are urged to migrate to secure versions as follows: Version 20.9 to 20.9.8.2, Version 20.11 to 20.12.6.1, Version 20.12 to both 20.12.5.3 and 20.12.6.1, and versions 20.13, 20.14, and 20.15 to 20.15.4.2. Meanwhile, versions 20.16 and 20.18 should be updated to 20.18.2.1.

Cisco advises users to apply these patches promptly. Additional security measures include restricting access from unsecured networks, placing appliances behind a firewall, disabling unnecessary network services, and changing default passwords. Continuous monitoring of network logs for unusual activity is also recommended.

Ongoing Security Challenges

This announcement follows a recent disclosure by Cisco regarding a critical flaw in both the Catalyst SD-WAN Controller and Manager, which received a maximum CVSS score of 10.0. This flaw was exploited by a sophisticated cyber adversary, UAT-8616, to infiltrate high-value organizations. Further, Cisco has addressed severe vulnerabilities in its Secure Firewall Management Center, which could allow attackers to bypass authentication.

The escalation in exploitation activities highlights the importance of maintaining updated security systems and being vigilant against potential threats. As cyber threats become increasingly sophisticated, organizations are encouraged to adopt comprehensive security strategies to safeguard their digital infrastructure.

The Hacker News Tags:Cisco, Cybersecurity, data breach, enterprise security, Exploitation, network security, patch update, SD-WAN, Software Security, Vulnerabilities

Post navigation

Previous Post: Critical MongoDB Flaw Exposes Servers to Attacks
Next Post: Malware Campaign Targets Crypto Pros with Fake LinkedIn VCs

Related Posts

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices The Hacker News
36 Malicious npm Packages Exploit Databases for Persistent Access 36 Malicious npm Packages Exploit Databases for Persistent Access The Hacker News
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE The Hacker News
Citrix Urges Immediate Patching of Critical NetScaler Flaws Citrix Urges Immediate Patching of Critical NetScaler Flaws The Hacker News
Understanding Magecart Threats in Web Supply Chains Understanding Magecart Threats in Web Supply Chains The Hacker News
Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vercel Data Breach: Security Measures and Investigation
  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber
  • AI-Powered Exploit Reveals Chrome Vulnerability Risks
  • Apple Aims to Fix iPhone Bug Removing Czech Character
  • Emerging Nexcorium Botnet Exploits DVR Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vercel Data Breach: Security Measures and Investigation
  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber
  • AI-Powered Exploit Reveals Chrome Vulnerability Risks
  • Apple Aims to Fix iPhone Bug Removing Czech Character
  • Emerging Nexcorium Botnet Exploits DVR Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark