EXPOSURES › CVE-2025-34026
CVE-2025-34026
HIGH ⌖ ON CISA KEV · EXPLOITEDVersa Concerto exposed improper authentication, allowing unauthorized access to administrative endpoints and sensitive data.
Versa Concerto, a SD-WAN orchestration platform, had an unpatched vulnerability in its Traefik reverse proxy configuration that enabled attackers to access administrative endpoints via the Actuator endpoint, potentially exposing heap dumps and trace logs. This is a high-severity issue actively exploited in the wild. DIB orgs should immediately assess and remediate their deployments.
Shame score — Active exploitation in the wild indicates negligence and a failure to maintain security postures.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.