Vulnerabilities · 187 days ago

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2022-20775 (Cisco Catalyst SD‑WAN path traversal) and CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller/Manager authentication bypass). Federal agencies must remediate these under BOD 22-01; all organizations are urged to prioritize patching or mitigations to reduce exposure.

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

CVE-2022-20775

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96th percentile), up from 0.4%.

CISA federal remediation date Feb 27 · date passed

Timeline

Sources

6 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-25

Editions

Related stories