← All Advisories

Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed

Last refreshed2026-09-27

Status: KEV  |  Advisory ID: CVE-2026-20128

Key Details

CVECVE-2026-20128
Vulnerability NameCisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Affected productsCisco Catalyst SD-WAN Manager
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-257 (Storing Passwords in a Recoverable Format)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-20.
Exploitation prediction (EPSS)7.80% probability of exploitation in the next 30 days (94% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-04-23 (CISA KEV, Binding Operational Directive).

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoCatalyst SD-WAN Manager
SubsystemsIndustrial Network - Routers/Firewalls
SectorsMultiple

What to Know

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

What to Do

Monitor Cisco's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20128
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20128

KEV Required Action

FieldValue
KEV Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Date Added to KEV2026-04-20
Required Action Due Date2026-04-23
Required ActionPlease adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.