Skip to main content
CISA Known Exploited Vulnerabilities

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2026-04-20
Remediation due
2026-04-23

Required action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CISA notes
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20133

Description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Severity

CVSS 3.1 · CNA6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
CiscoCisco Catalyst SD-WAN Manager
17.2.6
17.2.7
17.2.8
17.2.9
17.2.10
17.2.4
17.2.5
18.3.1.1
18.3.3.1
18.3.3
18.3.4
18.3.5
18.3.7
18.3.8
18.3.6.1
18.3.1
18.3.0
18.4.0.1
18.4.3
18.4.302
18.4.303
18.4.4
18.4.5
18.4.0
18.4.1
18.4.6
19.2.0
19.2.097
19.2.099
19.2.1
19.2.2
19.2.3
19.2.31
19.2.929
19.2.4
20.1.1.1
20.1.12
20.1.1
20.1.2
20.1.3
19.3.0
19.1.0
18.2.0
20.3.1
20.3.2
20.3.2.1
20.3.3
20.3.3.1
20.3.4
20.3.4.1
20.3.4.2
20.3.5
20.3.6
20.3.7
20.3.7.1
20.3.4.3
20.3.5.1
20.3.7.2
20.3.8
20.4.1
20.4.1.1
20.4.1.2
20.4.2
20.4.2.2
20.4.2.1
20.4.2.3
20.5.1
20.5.1.2
20.5.1.1
20.6.1
20.6.1.1
20.6.2.1
20.6.2.2
20.6.2
20.6.3
20.6.3.1
20.6.4
20.6.5
20.6.5.1
20.6.5.3
20.6.1.2
20.6.3.2
20.6.4.1
20.6.5.2
20.6.5.4
20.6.3.3
20.6.4.2
20.6.3.0.45
20.6.3.0.46
20.6.3.0.47
20.6.3.4
20.6.4.0.21
20.6.5.1.10
20.6.5.1.11
20.6.5.1.7
20.6.5.1.9
20.6.5.2.4
20.6.5.5
20.6.5.2.8
20.6.5.1.13
20.6.6
20.6.7
20.6.8
20.7.1
20.7.1.1
20.7.2
20.8.1
20.9.1
20.9.2
20.9.2.1
20.9.3
20.9.3.1
20.9.2.3
20.9.3.0.12
20.9.3.0.16
20.9.3.0.17
20.9.3.0.18
20.9.3.0.20
20.9.3.0.21
20.9.3.2
20.9.3.2_LI_Images
20.9.4
20.9.4_LI_Images
20.9.3.0.23
20.9.4.1
20.9.5
20.9.5.1
20.9.5.2
20.9.6
20.9.5.3
20.9.7
20.9.7.1
20.9.8
20.10.1
20.10.1.1
20.10.1.2
20.11.1
20.11.1.1
20.11.1.2
20.12.1
20.12.1_LI_Images
20.12.2
20.12.3
20.12.3.1
20.12.4
20.12.4.1
20.12.5
20.12.5.1
20.12.5.2
20.12.6
20.13.1
20.14.1
20.15.1
20.15.2
20.15.3
20.15.3.1
20.15.4
20.15.4.1
20.16.1
20.18.1
20.18.2

References

1 Links

Record Details

Published
2026-02-25
Last updated
2026-04-22
Assigner (CNA)
cisco
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.