peter bassill · operator
$ cve CVE-2025-34026 JSON

CVE-2025-34026 KEV

7.5
HIGH · CVSS 3.1 · EPSS 81.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-02-12.

Description

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS81.94% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-288
On CISA KEVyes — remediate by 2026-02-12
Public exploitnone known
Published2025-05-21
Last modified2026-06-17

CISA KEV

NameVersa Concerto Improper Authentication Vulnerability
Added2026-01-22
Due2026-02-12
Vendor / productVersa / Concerto
Ransomware usenone reported

Affected (1)

VendorProduct
versa-networksconcerto

References

→ the Explorer  ·  watch your stack  ·  NVD