Skip to main content
MEDIUM CISA KEV Actively Exploited

CVE-2026-20122

Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

CVSS v3

5.4

MEDIUM

EPSS Score

1.1 %

exploit probability

CISA KEV

Yes

known exploited

Exploitation

active

SSVC status

Description

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful expl

CISA Known Exploited Vulnerability

Date Added
2026-04-20
Patch Due Date
2026-04-23
Ransomware Use
Unknown

Technical details

CVSS v3 Vector
3.1
Published
2026-02-25
Last Modified
2026-04-21

Frequently asked questions

What is CVE-2026-20122?

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful expl

Is CVE-2026-20122 actively exploited?

Yes. CVE-2026-20122 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 4/23/2026.

What is the CVSS score for CVE-2026-20122?

CVE-2026-20122 has a CVSS v3 base score of 5.4 (MEDIUM severity), with vector string 3.1.

Is CVE-2026-20122 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 30 free checks/month · Free API key