Summarize with:

Share
Cisco updated an advisory to confirm active exploitation of two vulnerabilities affecting Catalyst SD-WAN Manager (formerly vManage), the centralized management plane used to administer large SD-WAN deployments. When a management plane is compromised, attackers can often pivot into the wider network and persist.
Cisco says it has observed active exploitation of:
Cisco also notes these issues impact Catalyst SD-WAN Manager regardless of configuration and recommends upgrading to fixed releases.
Even when exploitation requires credentials, real-world compromise paths are common: credential reuse, stolen VPN creds, infostealers, leaked API keys, or low-privilege access from another foothold.
For organizations running SD-WAN at scale, the management plane is a high-value target because it can:
BleepingComputer — Cisco flags more SD-WAN flaws as actively exploited in attacks (March 2026): https://www.bleepingcomputer.com/news/security/cisco-flags-more-sd-wan-flaws-as-actively-exploited-in-attacks/
Note: This post is a summary for security teams. Always follow the vendor advisory for the authoritative upgrade matrix.
Written by
Research
A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.
Get the latest cybersecurity insights in your inbox.
vulnerabilityCVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority CVE-2026-20182 is not landing as a routine patch bulletin. Cisco says the flaw is already b...
vulnerabilityExim BDAT flaw makes mail servers urgent RCE patch targets CVE-2026-45185 is the kind of bug that forces defenders to remember an old lesson: email infrastructu...
vulnerabilityDirty Frag Linux kernel zero-day gives local users a fast path to root Dirty Frag is the kind of Linux bug defenders worry about because it turns a limited foot...