🟢 CVE-2026-20128

CVE-2026-20128 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager that exposes DCA user credentials in a readable file. The CVSS shows LOCAL attack vector, requiring high privileges and high complexity, making direct internet exploitation unlikely despite CISA KEV listing.

← Back to Overview
LOW_RISK
Risk Level
7.5
CVSS Score
LOCAL
Attack Vector
Initial Access
ATT&CK Tactic
T1078 — Valid Accounts
ATT&CK Technique
LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: OTHER

CVE Published: 2026-02-25

Added to CISA KEV: 2026-04-20 54 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2026-20128 is a high-severity vulnerability affecting Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) [1]. It has been confirmed as being actively exploited in the wild and is included in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog [2] [3].

Vulnerability Details and Impact
  • Nature of the Vulnerability: The issue stems from the presence of a credential file for the Data Collection Agent (DCA) user on the affected system, which stores passwords in a recoverable format?id=CVE-2026-20128?kagi_q=CVE-2026-20128 [2].
  • Impact: Successful exploitation allows an attacker to gain DCA user privileges on the system [5]. This can lead to further compromise, including the ability to access sensitive information, elevate privileges to root, and overwrite arbitrary files on the system [4].
Exploitation Requirements
  • Attack Vector: While some sources describe the requirement as an authenticated, local attacker [5], other reports indicate that it can be exploited via crafted HTTP requests to retrieve sensitive credential files [1].
  • User Interaction: No specific user interaction is typically required for the exploitation once the attacker has the necessary access or capability to send the crafted requests.
Exploitation and Threat Activity
  • Active Exploitation: Cisco confirmed that the vulnerability is being actively exploited in the wild [3].
  • Targeted Attacks: Given its inclusion in the CISA KEV catalog and its role in managing critical network infrastructure, it is considered a significant target for malicious actors seeking to compromise network management systems [1].
  • Proof-of-Concept/Exploit Tools: While specific public exploit scripts may exist, the active exploitation in the wild confirms that functional exploit methods are available to threat actors.
Mitigation and Patch Status
  • Patch Status: Cisco has released software updates to address this vulnerability [4].
  • Recommendation: Organizations using Cisco Catalyst SD-WAN Manager are strongly advised to apply the latest security patches provided by Cisco immediately to mitigate the risk of exploitation [3].

Sources

  1. CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Vulnerability | UpGuard

    CVE-2026-20128 is a high-severity vulnerability (CVSS 7.5) in Cisco Catalyst SD-WAN Manager that is currently listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog. It allows unauthenticated attackers to retrieve sensitive credential files via crafted HTTP requests, gaining Data Collection…

  2. CISA Adds Eight Known Exploited Vulnerabilities to Catalog

    CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability; CVE-2026-20133 Cisco Catalyst SD-WAN ...

  3. Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager ...

    Cisco warns CVE-2026-20122 and CVE-2026-20128 in Catalyst SD-WAN Manager are actively exploited; patches released across multiple software versions.

  4. Cisco Catalyst SD-WAN Vulnerabilities

    Indicators of compromise for the exploitation of CVE-2026-20128 and CVE-2026-20122 are as follows. CVE-2026-20128: Cisco Catalyst SD-WAN Manager ... Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privi…

  5. CVE-2026-20128 - GitHub Advisory Database

    A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vul…