CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2022-20775 (Cisco Catalyst SD‑WAN path traversal) and CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller/Manager authentication bypass). Federal agencies must remediate these under BOD 22-01; all organizations are urged to prioritize patching or mitigations to reduce exposure.
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100º percentile).
Data di correzione federale CISA 27 feb · data superata
CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96º percentile), in aumento rispetto a 0.4%.
Data di correzione federale CISA 27 feb · data superata
Patched vulnerabilities in Ivanti Endpoint Manager and Cisco Catalyst SD-WAN are under attack, according to the US security agency, which added reporting requirements to its previous Cisco directive.
The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies until Thursday to patch CVE-2025-26399 — a critical vulnerability impacting the popular SolarWinds Web Help Desk.