Cisco Catalyst SD-WAN Manager Active Exploitation — Arbitrary File Overwrite and Credential Exposure (CVE-2026-20122, CVE-2026-20128) — Threadlinqs Intelligence
As of 2026-05-30, Cisco Catalyst SD-WAN Manager Active Exploitation — Arbitrary File Overwrite and Credential Exposure (CVE-2026-20122, CVE-2026-20128) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0185 · Severity: CRITICAL · CVSS: 7.5 · Status: MONITORING · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Two actively exploited vulnerabilities in Cisco Catalyst SD-WAN Manager (formerly Viptela vManage) are being chained by threat actors to deploy web shells on SD-WAN management appliances globally.
Two critical vulnerabilities in Cisco Catalyst SD-WAN Manager are under active exploitation as of early March 2026, part of a broader campaign targeting Cisco SD-WAN infrastructure that has been ongoing since at least 2023.
CVE-2026-20122 (CVSS 5.4, CWE-648) is an arbitrary file overwrite vulnerability in the Cisco Catalyst SD-WAN Manager API. The root cause is twofold: (1) API endpoints validate authentication but fail to enforce write-permission checks, allowing read-only users to execute file write operations, and (2) user-controlled file destination paths lack adequate sanitization, enabling directory traversal attacks. An authenticated remote attacker with only read-only API credentials can overwrite arbitrary files on the local filesystem, gaining vmanage user privileges. The attack surface is the HTTPS management interface on ports 443/8443. This vulnerability is frequently chained with authentication bypass flaws to achieve unauthenticated exploitation.
CVE-2026-20128 (CVSS 7.5, CWE-257) is an information disclosure and privilege escalation vulnerability in the Data Collection Agent (DCA) feature. An unprotected credential file containing the DCA user password is accessible to any user with valid vManage filesystem access. An authenticated local attacker can read this file and use the extracted credentials to gain DCA user privileges, potentially enabling lateral movement across the SD-WAN management infrastructure. Versions 20.18 and later are not affected by this specific CVE.
These vulnerabilities exist alongside CVE-2026-20127 (CVSS 10.0), a critical authentication bypass in the SD-WAN Controller that has been exploited by sophisticated threat actor UAT-8616 since 2023 to establish persistent footholds in high-value organizations. The broader campaign involves software version downgrades, exploitation of CVE-2022-20775 for root escalation, and stealth restoration of original firmware.
watchTowr observed exploitation attempts from numerous unique IP addresses with a peak on March 4, 2026. Threat actors are deploying web shells on exposed SD-WAN Manager instances, overwriting files via the API vulnerability to plant persistent backdoors. Attack activity is globally distributed with slightly elevated targeting of U.S.-based infrastructure.
CISA issued Emergency Directive ED 26-03 on February 26, 2026, requiring federal agencies to inventory systems, collect forensic artifacts, apply patches, and hunt for compromise indicators. The Australian ASD-ACSC, Canadian CCCS, and other Five Eyes partners issued a joint advisory. Cisco patched the vulnerabilities on February 25, 2026, but exploitation intensified after patch release due to rapid weaponization.
The affected product — Cisco Catalyst SD-WAN Manager — is a critical network management plane component used by enterprises, service providers, and government agencies to orchestrate and manage SD-WAN overlay networks. Compromise of vManage provides attackers with visibility into and control over the entire SD-WAN fabric, including routing policies, traffic flows, and connected edge devices.
---
**Revalidated on 2026-03-12**
This threat has been significantly escalated since its initial publication. On March 5, 2026, Cisco PSIRT confirmed active in-the-wild exploitation of both CVE-2026-20122 (arbitrary file overwrite via API, CVSS 7.1) and CVE-2026-20128 (DCA credential exposure enabling cross-instance lateral movement, CVSS 5.5). These vulnerabilities are being exploited as part of a broader, highly sophisticated campaign tracked by Cisco Talos as UAT-8616, which has been targeting Cisco SD-WAN infrastructure globally since at least 2023. The campaign initially leveraged CVE-2026-20127 (CVSS 10.0 authentication bypass) for initial access, then chained CVE-2022-20775 for root privilege escalation via software version downgrade — a technique designed to evade forensic detection by reverting to the original version after exploitation. The exploitation of CVE-2026-2
Weaknesses (CWE)
CWE-648, CWE-257
Target sectors: government, telecommunications, financial, healthcare, defense, critical-infrastructure, service-providers, enterprise
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20122, CVE-2026-20128, T1190, T1078, T1059, T1505, T1098, T1547, T1136, T1068, T1070, T1562