CVE-2026-20128
9.5 CISA KEVCisco · Catalyst SD-WAN Manager
A vulnerability in the Data Collection Agent of Cisco Catalyst SD-WAN Manager allows remote attackers to retrieve stored credentials via crafted HTTP requests and gain unauthorized privileges.
Executive summary
Cisco Catalyst SD-WAN Manager is vulnerable to a critical credential exposure flaw that is currently being actively exploited in the wild to gain unauthorized system access.
Vulnerability
This flaw exists in the Data Collection Agent (DCA) feature, where a credential file containing the DCA password is stored in a recoverable format. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to read the file, subsequently gaining DCA user privileges on the system.
Business impact
This vulnerability carries a CVSS score of 9.5, reflecting its critical nature and the high risk of total system compromise. Successful exploitation enables attackers to gain elevated privileges, which can facilitate lateral movement within the network, unauthorized data access, and the deployment of persistent threats such as web shells. Given its inclusion in the CISA Known Exploited Vulnerabilities catalog, the urgency for remediation is extreme to prevent operational disruption and data theft.
Remediation
Immediate Action: Upgrade to Cisco Catalyst SD-WAN Manager release 20.18 or later immediately to eliminate the insecure credential storage mechanism.
Proactive Monitoring: Review system logs for anomalous HTTP requests targeting the Data Collection Agent and monitor for the presence of unauthorized web shells or unexpected service account activity.
Compensating Controls: Implement strict network segmentation and egress filtering to limit the exposure of the SD-WAN management interface to untrusted networks, and apply Web Application Firewall rules to block suspicious HTTP requests.
Exploitation status
Public Exploit Available: Yes, public proof-of-concept code was released in March 2026.
Analyst recommendation
The combination of a 9.5 CVSS score, confirmed active exploitation, and the presence of public proof-of-concept code necessitates an immediate response. Organizations must prioritize the update to version 20.18 or later across all impacted Cisco Catalyst SD-WAN Manager instances. Failure to remediate this vulnerability significantly increases the risk of successful adversary compromise and long-term persistence within the environment.