🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Cisco Catalyst SD-WAN Manager Password Storage Privilege Escalation (CVE-2026-20128) | MSSP Advisory

Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-20128
CVSS Score7.5
Affectedcatalyst_sd-wan_manager
📋Executive Summary
CISA added CVE-2026-20128 to the KEV catalog, exposing a password storage flaw in Cisco Catalyst SD-WAN Manager that lets local attackers escalate to admin privileges. This affects both your internal network management and client environments running these devices.
⚠️Why It Matters for MSSPs
Your RMM tools and remote access likely touch these SD-WAN devices, making your infrastructure a pathway to client networks if compromised. Every client with Cisco SD-WAN expects you to know about this privilege escalation risk and guide them through emergency patching.
Recommended Action
Inventory all Cisco SD-WAN Manager instances across your stack and client environments within 24 hours. Apply CISA Emergency Directive 26-03 mitigations immediately or disconnect devices that cannot be patched before the April deadline.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.