CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2022-20775 (Cisco Catalyst SD‑WAN path traversal) and CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller/Manager authentication bypass). Federal agencies must remediate these under BOD 22-01; all organizations are urged to prioritize patching or mitigations to reduce exposure.
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).
CISA federal remediation date Feb 27 · date passed
CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96th percentile), up from 0.4%.
CISA federal remediation date Feb 27 · date passed
Patched vulnerabilities in Ivanti Endpoint Manager and Cisco Catalyst SD-WAN are under attack, according to the US security agency, which added reporting requirements to its previous Cisco directive.
The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies until Thursday to patch CVE-2025-26399 — a critical vulnerability impacting the popular SolarWinds Web Help Desk.