CISA has added three Cisco Catalyst SD-WAN vulnerabilities to its Known Exploited Vulnerabilities catalog, including one that has not been publicly disclosed as being exploited previously.

The three newly added bugs are CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133, the last of which had not been identified in active attacks before. That bug is an access permissions issue that could lead to data theft.

“This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system,” the Cisco advisory says. 

That vulnerability affects a long list of Catalyst SD-WAN Manager versions, and Cisco released updates for it in February, but on Tuesday CISA added it to the KEV, along with several other bugs. Although the bug has been public knowledge for two months, it’s not unusual for exploitation activity to emerge weeks or months after an initial disclosure like this. 

The other Cisco flaws added to the KEV, CVE-2026-20122 and CVE-2026-20128, had been identified as being publicly exploited before, and Cisco had said as much in its advisory.  

“This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges,” the advisory for CVE-2026-20128 says. 

CVE-2026-20133 is the fourth Catalyst SD-WAN vulnerability targeted by attackers in the last few months. In February, Cisco Talos released an analysis of a campaign by an unattributed threat actor targeting CVE-2026-20127. The NSA also released an advisory about that campaign at the time. 

“For over a year, malicious actors exploited vulnerabilities in Cisco SD-WANs. Most notably, by leveraging a previously unknown (zero-day) vulnerability, CVE-2026-20127, these actors introduced a malicious rogue peer, gained authenticated access, and established persistent, long-term presence within the compromised SD-WAN networks,” the NSA advisory says. 

The Cisco Catalyst SD-WAN products are widely deployed and threat actors have shown an affinity and capability for targeting them, so organizations that haven’t yet upgraded to the fixed versions of the software should do so as soon as possible.