CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2022-20775 (Cisco Catalyst SD‑WAN path traversal) and CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller/Manager authentication bypass). Federal agencies must remediate these under BOD 22-01; all organizations are urged to prioritize patching or mitigations to reduce exposure.

Part of the PlainSec briefing for 2026-03-25

Sources