Wednesday, April 22, 2026

Top stories: CISA flags new SD-WAN flaw as actively exploited in attacks Cybersecurity Dive BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks.

CISA flags new SD-WAN flaw as actively exploited in attacks

 CISA Alert: Cisco Catalyst SD-WAN Flaws Actively Exploited
Top stories

Federal agencies ordered to patch until Friday

CISA Presses Agencies to Secure Cisco SD-WAN Systems After Security  Exploited - The420.in

On Monday, CISA added CVE-2026-20133 to its Known Exploited Vulnerabilities (KEV) Catalog, "based on evidence of active exploitation," and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their networks until Friday, April 24.

"Please adhere to CISA's guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA's Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices," CISA said. "Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available."

Cisco has yet to confirm the U.S. cybersecurity agency's report that the flaw is being exploited in attacks, with its security advisory still saying that its Product Security Incident Response Team (PSIRT) is "not aware of any public announcements or malicious use of the vulnerabilities that are described in CVE-2026-20133."

In February, Cisco also tagged a critical authentication bypass vulnerability (CVE-2026-20127) as exploited in zero-day attacks that were enabling threat actors to add malicious rogue peers to targeted networks since at least 2023.

More recently, in early March, the company released security updates to address two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software that can allow attackers to gain root access to the underlying operating system and execute arbitrary Java code with root privileges.

CISA orders feds to patch Fortinet flaw exploited in attacks by Friday: The  U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered  federal agencies to secure FortiClient Enterprise Management Server (EMS)  instances against 

Over the last several years, CISA has tagged 91 Cisco vulnerabilities as exploited in the wild, six of which have been used by various ransomware operations.

BleepingComputer (@BleepinComputer) / Posts / X

== 

No comments:

Hacker News #1 Trusted Source for Cybersecurity News

About — The Hacker News THN Media Private Limited, the parent organization behind The Hacker News (THN), stands as a t...