{"id":11124,"date":"2026-03-05T10:03:52","date_gmt":"2026-03-05T10:03:52","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/05\/cisco-catalyst-sd-wan-vulnerabilities-allow-attackers-to-gain-root-access\/"},"modified":"2026-03-05T10:03:52","modified_gmt":"2026-03-05T10:03:52","slug":"cisco-catalyst-sd-wan-vulnerabilities-allow-attackers-to-gain-root-access","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/05\/cisco-catalyst-sd-wan-vulnerabilities-allow-attackers-to-gain-root-access\/","title":{"rendered":"Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access"},"content":{"rendered":"<p>    Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An urgent security advisory from Cisco warns that multiple vulnerabilities in <a href=\"https:\/\/cybersecuritynews.com\/cisco-sd-wan-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cisco Catalyst SD-WAN Manager<\/a> could allow attackers to bypass authentication, gain root access, and overwrite critical files.<\/p>\n<p>Two of these vulnerabilities are already being exploited in the wild by hackers, making immediate remediation critical.\u200b<\/p>\n<p>The advisory details five vulnerabilities, led by CVE-2026-20129, a critical <a href=\"https:\/\/cybersecuritynews.com\/cisco-will-not-fix-authentication-bypass-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication bypass flaw<\/a> with a CVSS score of 9.8.<\/p>\n<p>This bug allows a remote, unauthenticated attacker to send crafted API requests and instantly gain\u00a0netadmin\u00a0privileges.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cisco-catalyst-sd-wan-vulnerabilities\"><strong>Cisco Catalyst SD-WAN Vulnerabilities<\/strong><\/h2>\n<p>Another major threat is CVE-2026-20126, which enables a local user with low <a href=\"https:\/\/cybersecuritynews.com\/desktop-window-manager-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">privileges to escalate their access<\/a> to root on the underlying operating system.\u200b<\/p>\n<p>As of March 2026, Cisco warns that threat actors are actively exploiting CVE-2026-20122 and CVE-2026-20128. The first flaw allows attackers with read-only credentials to overwrite arbitrary system files and gain\u00a0vmanage\u00a0rights.<\/p>\n<p>The second issue targets the <a href=\"https:\/\/cybersecuritynews.com\/cisco-ios-xe-badcandy-web-shell\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data Collection Agent (DCA)<\/a>, allowing low-level users to steal plaintext passwords and spread their access to other affected systems.<\/p>\n<p>Because these are being used in real-world attacks, organizations face a high risk of compromise if they do not patch their systems immediately.<\/p>\n<p>Because there are no workarounds to block these attacks, <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-authbp-qwCX8D4v\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cisco strongly urges administrators to upgrade their software <\/a>immediately.<\/p>\n<p>Network defenders must apply the fixed software releases, such as versions 20.9.8.2, 20.12.5.3, or 20.18.2.1, depending on their current setup.<\/p>\n<p>Notably, Catalyst SD-WAN Manager releases 20.18 and later are naturally immune to both the critical authentication bypass and the actively exploited DCA flaw.\u200b<\/p>\n<p>Arthur Vidineyev from the Cisco Advanced Security Initiatives Group (ASIG) originally discovered these vulnerabilities during internal testing.<\/p>\n<p>To harden defenses, Cisco recommends restricting internet access to the SD-WAN Manager portal, turning off unused network services such as HTTP or FTP, and implementing strict firewall rules.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-catalyst-sd-wan-vulnerabilities\/\">Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-catalyst-sd-wan-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access An urgent security advisory from Cisco warns that multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow attackers to bypass authentication, gain root access, and overwrite critical files. Two of these vulnerabilities are already being exploited in the wild by hackers, making immediate remediation critical.\u200b [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1439,129,63,648],"tags":[130],"class_list":["post-11124","post","type-post","status-publish","format-standard","hentry","category-cisco","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11124"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11124"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11124\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}