PatchSiren cyber security CVE debrief
CVE-2026-20122 Cisco CVE debrief
CVE-2026-20122 is a Cisco Catalyst SD-WAN Manager vulnerability described as an incorrect use of privileged APIs. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-20 and set a remediation due date of 2026-04-23, which means defenders should treat it as urgent.
- Vendor
- Cisco
- Product
- Catalyst SD-WAN Manger
- CVSS
- MEDIUM 5.4
- CISA KEV
- Listed
- Original CVE published
- 2026-04-20
- Original CVE updated
- 2026-04-20
- Advisory published
- 2026-04-20
- Advisory updated
- 2026-04-20
Who should care
Organizations that operate Cisco Catalyst SD-WAN Manager or manage Cisco SD-WAN devices should prioritize this issue, especially teams responsible for perimeter exposure, centralized network management, and incident response.
Technical summary
The supplied source corpus describes the issue as an incorrect use of privileged APIs in Cisco Catalyst SD-WAN Manager. CISA’s KEV listing indicates that the vulnerability is known to be exploited in the wild. The source corpus does not provide deeper technical detail such as attack preconditions, authentication requirements, or impact scope, so those specifics should be confirmed in Cisco’s advisory and CISA’s guidance.
Defensive priority
High. CISA’s KEV inclusion and the short remediation window indicate immediate triage and mitigation are warranted.
Recommended defensive actions
- Determine whether Cisco Catalyst SD-WAN Manager or Cisco SD-WAN devices are present in your environment.
- Assess exposure and follow CISA Emergency Directive 26-03 mitigation guidance.
- Use CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices to look for signs of compromise and reduce attack surface.
- Apply Cisco’s vendor guidance from the official security advisory referenced by CISA.
- Follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are not available.
Evidence notes
This debrief is based on the supplied CISA KEV record and its linked official resources. The record identifies Cisco as the vendor, Catalyst SD-WAN Manager as the affected product, the vulnerability name as an incorrect use of privileged APIs issue, and KEV dates of 2026-04-20 added / 2026-04-23 due. No CVSS score or deeper exploit details were provided in the source corpus, so none are inferred here.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.