Critical Analysis: CVE-2026-20122 - Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged AP... — April 21, 2026

Published 21 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

Initial Discovery and Context We're seeing a critical vulnerability, CVE-2026-20122, surface in Cisco Catalyst SD-WAN Manager, a particularly sticky one that was published on April 21, 2026. This isn't just another bug; it’s an Incorrect Use of Privileged APIs flaw that allows an authenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges. Yeah, you read that right – root. The CVSSv3.1 score of 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) accurately reflects the severity. The 'Privileges Required: Low' (PR:L) is what truly elevates this to critical status. An attacker doesn't need to be an admin to leverage this; a standard user account is sufficient, which significantly broadens the attack surface. This vulnerability affects Cisco Catalyst SD-WAN Manager versions prior to 20.9.3, 20.10.2, 20.11.1, and 20.12.1. Given the widespread ad