CVE-2025-34026
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
81.9%
99.6th percentile
CISA KEV
Listed
Added 2026-01-22 · patch by 2026-02-12
Weakness / dates
—
Published — · modified —
Description
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.