CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
CISA added eight confirmed exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, setting an April 23 remediation deadline for federal agencies. Three of the eight target Cisco Catalyst SD-WAN Manager and allow unauthenticated remote access, credential theft, and malicious file upload.
CISA added eight newly confirmed exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog this week, with a hard April 23, 2026 remediation deadline for all Federal Civilian Executive Branch (FCEB) agencies. Three of the eight target Cisco Catalyst SD-WAN Manager directly.
The three Cisco SD-WAN CVEs:
- CVE-2026-20133 — Unauthenticated remote information disclosure. An attacker can query the management interface without credentials and extract sensitive system information. No CVSS score published at time of writing, but Cisco rates it High.
- CVE-2026-20128 — Credential file exposure enabling privilege escalation. An authenticated attacker with low-privilege access can read a credential file on disk and escalate to administrator. CVSS 8.8.
- CVE-2026-20122 — Malicious file upload. An authenticated attacker can upload a crafted file to achieve arbitrary code execution on the SD-WAN Manager appliance. CVSS 8.8.
Cisco confirmed CVE-2026-20128 and CVE-2026-20122 as actively exploited in the wild as early as March 2026. If you’re running Cisco Catalyst SD-WAN Manager in any version before the patched releases Cisco published last month, upgrade now. The management interface should never be internet-exposed regardless.
The remaining five CVEs span five different vendors:
- PaperCut NG/MF — Server-side request forgery (SSRF) allowing internal network access from the print server host.
- JetBrains TeamCity — Authentication bypass giving unauthenticated access to the build server’s REST API.
- Kentico Xperience — SQL injection in the content management layer enabling data exfiltration.
- Quest KACE Systems Management Appliance — Remote code execution via an unsafe deserialization vulnerability in the KACE agent.
- Synacor Zimbra Collaboration Suite — Cross-site scripting (XSS) that allows session hijacking when a victim views a malicious email.
The breadth of this KEV batch is notable. Cisco SD-WAN, JetBrains TeamCity, Zimbra, and PaperCut are all enterprise staples — the kind of software running in thousands of organizations that don’t treat their build servers or print management platforms as attack surfaces. They are.
What to do right now:
- Check your Cisco Catalyst SD-WAN Manager version against Cisco’s security advisory and apply the latest patch.
- Audit TeamCity access — if the REST API is reachable without authentication, something is misconfigured.
- PaperCut: disable the web interface from public internet access and apply the latest update.
- Zimbra and Kentico: check vendor advisories published this week for specific patch versions.
- Quest KACE: upgrade KACE agent and appliance firmware immediately.
CISA’s KEV catalog is authoritative signal. When CISA adds a flaw with an active-exploitation tag, it means threat actors are using it in live attacks — not just proof-of-concept. Treat April 23 as the ceiling, not the target date.
Related reading
- Cybersecurity Cisco Firewall Management Center Zero-Day (CVE-2026-20316) Exploited in the Wild — CISA Sets August 1 Deadline
- Cybersecurity CVE-2026-42897 (CVSS 8.1): Microsoft Exchange OWA Zero-Day Actively Exploited — No Patch Available
- Cybersecurity Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — CISA Orders Federal Patch by April 27