CISA's list that day
25 February 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Cisco SD-WAN and Cisco Catalyst SD-WAN Controller and Manager. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-20127Authentication Bypass | Cisco Catalyst SD-WAN Controller and Manager | Patch this weekMetasploit module; EPSS 0.88 | 0.88 | ||
| CVE-2022-20775Path Traversal | Cisco SD-WAN | Patch soon | 0.12 |