CVE-2025-34026CISA KEV: Actively Exploited

Versa Concerto Improper Authentication Vulnerability

Published Jan 22, 2026·Updated Jan 22, 2026

Description

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free