CVE-2026-20128
Cisco Catalyst SD-WAN Manager: Storing Passwords in a Recoverable Format
As of , CVE-2026-20128 in Cisco Catalyst SD-WAN Manager is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.
- Exploited
- Yes: CISA listed it on 20 April 2026
- US federal deadline
- 23 April 20263 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.07Higher than 94% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: sec.cloudapps.cisco.comLinks below, from CISA's entry.
What CISA says to do
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CISA's required action
What the flaw is
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
CISA's description
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
The CVE record's description, from cisco
- CVE published
- 25 February 2026
- Assigned by
- cisco
- CVSS
- 7.5 High (CVSS 3.1, from the CNA)
- CWE-257
- Storing Passwords in a Recoverable Format
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Catalyst SD-WAN Manager: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-76504Hex Encoding | Cisco Catalyst SD-WAN Manager | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| CVE-2026-20262Directory or Path Traversal | Cisco Catalyst SD-WAN Manager | Patch soon | 0.28 | ||
| CVE-2026-20133Exposure of Sensitive Information to an Unauthorized Actor | Cisco Catalyst SD-WAN Manager | Patch soon | 0.32 | ||
| CVE-2026-20245Improper Encoding or Escaping of Output | Cisco Catalyst SD-WAN Manager | Patch soon | 0.25 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org