External risk intelligence

Attacker can steal Cisco Catalyst SD-WAN Manager passwords to gain admin control

CVE advisoryKnown Exploit

CVE-2026-20128

Cisco Catalyst SD-WAN Manager may allow an attacker to steal credentials and gain control of your network. This is a high-risk vulnerability actively exploited by attackers, demanding immediate attention.

4Halo Surface Signal

Cisco Catalyst Sd Wan Manager

before 20.9.8.220.10 to before 20.12.5.320.13 to before 20.15.4.220.16 to before 20.1820.12.6

External exposure likelihood

Halo Surface Signal score for CVE-2026-20128

The vulnerability affects Cisco Catalyst SD-WAN Manager, a central management appliance. The attack requires sending a web request to an internet-facing management interface. As an administrative system, it is commonly deployed as an externally reachable management surface or gateway to facilitate network control, making it accessible over the network in many environments.

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Cisco Catalyst SD-WAN Manager that could allow an attacker to gain privileges as the Data Collection Agent (DCA) user. This happens because a password file for the DCA user is present on the system, and an attacker can read it with a crafted request. Gaining these privileges could then enable access to other affected systems.

  • Attacker can read DCA password.
  • Leads to unauthorized privileges.
  • Affects Cisco Catalyst SD-WAN Manager.

Attack Path

How an attacker could exploit the issue

An attacker who gains access to the system can exploit this by accessing a credential file containing the DCA user's password. This allows them to then use these stolen credentials to gain DCA user privileges on other affected systems.

  • Requires system access.
  • Targets DCA credential file.
  • Uses stolen credentials.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability has a high potential for exploitation, as it is present in a critical network management system and has been added to the CISA Known Exploited Vulnerabilities catalog. Attackers are likely to weaponize this type of vulnerability due to its ability to grant significant privileges on a widely deployed enterprise device.

  • Added to KEV catalog.
  • Exploitable via network request.
  • Affects management system.

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize patching Cisco Catalyst SD-WAN Manager to a non-vulnerable version immediately, as this vulnerability is actively exploited and allows for privilege escalation. If patching is delayed, implement network segmentation to isolate affected systems and strictly control access to the Data Collection Agent (DCA) user's credential file.

  • Update to a fixed version.
  • Isolate affected systems.
  • Monitor for unauthorized access.

Frequently asked questions

What is Cisco Catalyst SD-WAN Manager?

Cisco Catalyst SD-WAN Manager is a central management system used to control and monitor Cisco's Software-Defined Wide Area Networking (SD-WAN) solutions. It allows administrators to configure, deploy, and manage network devices and policies across an organization's network infrastructure.

What weakness class does CVE-2026-20128 fall under?

CVE-2026-20128 is related to the weakness class CWE-257, which involves storing passwords in a recoverable format. In this case, a password file for the Data Collection Agent (DCA) user is present on the system, making it susceptible to compromise.

What are the preconditions for an attacker to exploit this CVE?

An attacker needs to be able to send a crafted HTTP request to an affected system. The vulnerability is triggered when this request allows the attacker to read a file containing the DCA user's password. A successful exploit allows the attacker to then gain DCA user privileges.

Who should care about CVE-2026-20128?

Organizations using Cisco Catalyst SD-WAN Manager should care about this vulnerability. Because the attack requires sending a web request to a management interface, and this type of system is often exposed to the network, it's classified as likely to be relevant to internet-facing assets.

What is the first step to address this CVE?

The immediate first step is to update Cisco Catalyst SD-WAN Manager to a version that is not affected by this vulnerability, such as releases 20.18 and later. If immediate patching is not possible, implementing network segmentation to isolate affected systems is recommended.

References