| Date | Source | Article |
|---|---|---|
| 2026-05-26 | FortiGuard Labs Threat Signal | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127 |
Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2026-20127 | 10.0 Critical | Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypas… |
| CVE-2026-20129 | 9.8 Critical | Cisco Cisco Catalyst SD-WAN Manager A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an … |
| CVE-2026-20126 | 8.8 High | Cisco Cisco Catalyst SD-WAN Manager A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the unde… |
| CVE-2022-20775 | 7.8 High | Cisco SD-WAN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper ac… |
| CVE-2026-20128 | 7.5 High | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain… |
| CVE-2026-20133 | 6.5 Medium | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers … |
| CVE-2026-20122 | 5.4 Medium | Cisco Catalyst SD-WAN Manger Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an aff… |
Extracted from the publication text. Each CVE links to its tracked detail page.
Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.