Cisco fixed seven exploited Catalyst SD-WAN flaws on the 20.9 line this year. Its End of Vulnerability/Security Support is September 30, 2026.
Seven exploited flaws, seven 20.9 fixes
| CVE | What it is | CVSS | Added to CISA KEV | First fixed 20.9 build |
|---|---|---|---|---|
| CVE-2026-20127 | Peering authentication bypass on SD-WAN Controller, Manager and Validator; unauthenticated, remote | 10.0 | February 25, 2026 | 20.9.8.2 |
| CVE-2026-20128 | Data Collection Agent credential file lets an unauthenticated attacker gain DCA user privileges on SD-WAN Manager | 7.5 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20122 | Arbitrary file overwrite through the SD-WAN Manager API; needs read-only API credentials | 5.4 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20133 | Insufficient file-system restrictions expose sensitive files to an authenticated netadmin user | 6.5 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20182 | Second authentication bypass, in control-connection handshaking, found and fixed after the February disclosure | 10.0 | May 14, 2026 | 20.9.9.1 |
| CVE-2026-20245 | CLI privilege escalation to root for an authenticated local netadmin; Cisco saw it used after CVE-2026-20182 or CVE-2026-20127 | 7.8 | June 9, 2026 | 20.9.9.2 |
| CVE-2026-20262 | Arbitrary file write through the SD-WAN Manager web UI; authenticated, remote | 6.5 | June 15, 2026 | 20.9.9.2 |
What's covered
- Seven exploited flaws, seven 20.9 fixes
- What the same advisories say about lines outside the window
- Where a 20.9 fabric goes next
- What to do before the date
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-cisco-sdwan-20-9-security-support-ends-2026
Top comments (0)