๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Summary
Cisco Catalyst SD-WAN Manager has a vulnerability where passwords are stored in a recoverable format (meaning they can be decoded or extracted), allowing an authenticated, local attacker with low-level access to read a credential file and gain higher privileges. This vulnerability is currently being exploited by attackers in the real world.
Solution / Mitigation
According to CISA, organizations should adhere to CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess exposure and mitigate risks. Organizations must also follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. The due date for remediation is April 23, 2026.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
April 19, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-20128
First tracked: April 20, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%