Vulnerabilities & Exploits · Web App Attack

CISA Adds Four Actively Exploited Vulnerabilities to KEV

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Affected products include Cisco Catalyst SD‑WAN, multiple Qualcomm chipsets, and Broadcom VMware Aria Operations.

6 sources · Mar 15

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

CVE-2022-20775

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96th percentile), up from 0.4%.

CISA federal remediation date Feb 27 · date passed

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-04

Every edition of this story: CISA Adds Four Actively Exploited Vulnerabilities to KEV

More from today