[CVE-2026-20129, CVSS: 9.8] This vulnerability exists in the
API user authentication of the Cisco Catalyst SD-WAN Manager. It allows an unauthenticated remote attacker to use a carefully crafted
API request to access the affected system as a user with the netadmin role. Note: The Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage) have been found to be actively exploited in attack campaigns; please take responsive measures immediately.