Dossier
CVE-2026-20128
Coverage of CVE-2026-20128 in the Nexus archive.
- Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
Cisco's SD-WAN management software is under attack due to a high-severity zero-day vulnerability (CVE-2026-20245), which allows authenticated attackers to escalate privileges and execute commands. Cisco has not yet released a patch, and this is the sixth SD-WAN vulnerability exploited since the year began.