← Browse

CVE-2025-34026

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
81.9%
99.6th percentile
CISA KEV
Listed
Added 2026-01-22 · patch by 2026-02-12
Weakness / dates
Published — · modified —

Description

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

Official: NVD · CVE.org