🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Cisco Catalyst SD-WAN Manager Privilege Escalation File Upload (CVE-2026-20122) | MSSP Advisory
Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-20122
CVSS Score5.4
Affectedcatalyst_sd-wan_manager
📋Executive Summary
CISA added CVE-2026-20122 to the Known Exploited Vulnerabilities catalog targeting Cisco Catalyst SD-WAN Manager with a file upload flaw that grants system privileges. The vulnerability allows attackers to overwrite system files and escalate to vmanage user privileges through malicious file uploads.
⚠️Why It Matters for MSSPs
Your RMM and client management infrastructure likely depends on SD-WAN devices that could be compromised through this attack vector, giving threat actors persistent access to your operational stack. Clients running Cisco SD-WAN infrastructure expect immediate guidance on exposure assessment and mitigation steps before attackers exploit unpatched systems.
✅Recommended Action
Audit all client environments for Cisco Catalyst SD-WAN Manager deployments within 24 hours and cross-reference against CISA Emergency Directive 26-03 requirements. Execute the Hunt & Hardening Guidance protocols immediately on identified systems and prepare client communications explaining exposure status and remediation timelines.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.