PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20122 Cisco CVE debrief

CVE-2026-20122 is a Cisco Catalyst SD-WAN Manager vulnerability described as an incorrect use of privileged APIs. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-20 and set a remediation due date of 2026-04-23, which means defenders should treat it as urgent.

Vendor
Cisco
Product
Catalyst SD-WAN Manger
CVSS
MEDIUM 5.4
CISA KEV
Listed
Original CVE published
2026-04-20
Original CVE updated
2026-04-20
Advisory published
2026-04-20
Advisory updated
2026-04-20

Who should care

Organizations that operate Cisco Catalyst SD-WAN Manager or manage Cisco SD-WAN devices should prioritize this issue, especially teams responsible for perimeter exposure, centralized network management, and incident response.

Technical summary

The supplied source corpus describes the issue as an incorrect use of privileged APIs in Cisco Catalyst SD-WAN Manager. CISA’s KEV listing indicates that the vulnerability is known to be exploited in the wild. The source corpus does not provide deeper technical detail such as attack preconditions, authentication requirements, or impact scope, so those specifics should be confirmed in Cisco’s advisory and CISA’s guidance.

Defensive priority

High. CISA’s KEV inclusion and the short remediation window indicate immediate triage and mitigation are warranted.

Recommended defensive actions

  • Determine whether Cisco Catalyst SD-WAN Manager or Cisco SD-WAN devices are present in your environment.
  • Assess exposure and follow CISA Emergency Directive 26-03 mitigation guidance.
  • Use CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices to look for signs of compromise and reduce attack surface.
  • Apply Cisco’s vendor guidance from the official security advisory referenced by CISA.
  • Follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are not available.

Evidence notes

This debrief is based on the supplied CISA KEV record and its linked official resources. The record identifies Cisco as the vendor, Catalyst SD-WAN Manager as the affected product, the vulnerability name as an incorrect use of privileged APIs issue, and KEV dates of 2026-04-20 added / 2026-04-23 due. No CVSS score or deeper exploit details were provided in the source corpus, so none are inferred here.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-20122 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-20122

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-20122 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20122

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.