PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-20775 Cisco CVE debrief

CVE-2022-20775 is a Cisco SD-WAN path traversal vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-25, with a mitigation due date of 2026-02-27. Because the supplied source corpus is limited to catalog and record metadata, this brief focuses on defensive prioritization: confirm whether any Cisco SD-WAN devices are exposed, follow Cisco’s official advisory and CISA’s Emergency Directive 26-03 and hunt-and-hardening guidance, and verify that any required mitigations are in place.

Vendor
Cisco
Product
SD-WAN
CVSS
HIGH 7.8
CISA KEV
Listed
Original CVE published
2026-02-25
Original CVE updated
2026-02-25
Advisory published
2026-02-25
Advisory updated
2026-02-25

Who should care

Network and security teams responsible for Cisco SD-WAN, incident response and threat hunting teams, vulnerability management, and any organization using Cisco SD-WAN devices or related cloud-managed services.

Technical summary

The available source data identifies the issue as a path traversal vulnerability in Cisco SD-WAN. The corpus does not include affected versions, CVSS scoring, or exploit mechanics, so no further technical detail should be assumed from this debrief. The key operational fact is CISA KEV inclusion, which indicates that organizations should treat exposure as time-sensitive and validate mitigations against Cisco’s official advisory and CISA guidance.

Defensive priority

High. KEV listing plus a near-term due date means this should be treated as an urgent remediation and exposure-validation item, even though the supplied corpus does not include severity scoring.

Recommended defensive actions

  • Identify all Cisco SD-WAN devices, including cloud-managed deployments, and confirm whether they are in scope for the advisory.
  • Review Cisco’s official SD-WAN advisory and CISA Emergency Directive 26-03 plus the hunt-and-hardening guidance.
  • Apply vendor-recommended mitigations or compensating controls as directed by Cisco and CISA.
  • Validate compliance with applicable BOD 22-01 guidance for cloud services; if mitigations are not available, follow the cited CISA direction regarding discontinuing use of the product.
  • Perform authorized defensive hunting for suspicious access or compromise indicators.
  • Track remediation status and retest exposure after changes are made.

Evidence notes

Source corpus is limited to the CISA KEV catalog entry, CVE record link, NVD detail link, and CISA guidance references embedded in the KEV metadata. The corpus identifies the vulnerability as a Cisco SD-WAN path traversal issue and records CISA dates of 2026-02-25 (date added) and 2026-02-27 (due date). No CVSS score, affected-version list, or exploit narrative was supplied, so those details are intentionally omitted.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-20775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-20775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-20775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-20775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.