>> All posts

CVE-2026-20133: Cisco Catalyst SD-WAN Manager information disclosure, exploited in the wild

The short version: CVE-2026-20133 lets an unauthenticated, remote attacker read sensitive information from Cisco Catalyst SD-WAN Manager by querying its API, because of insufficient file-system access restrictions. On its own it's information disclosure, but it's been exploited in the wild — chained with two related flaws to gain access — and it's in CISA's KEV catalog. If you self-host SD-WAN Manager, patch and verify. Steady hands, but move.

At a glance

FactDetail
Our severity takeHigh — info disclosure, but KEV-listed and used in an exploitation chain
CVSS v3.1 (NVD)7.5 — High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS (Cisco)6.5 — Medium
EPSS10.25% · 95.17th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2026-04-23
Known exploited?Yes — active in-the-wild exploitation, chained with CVE-2026-20128 and CVE-2026-20122
Vulnerability typeCWE-200 information exposure via insufficient file-system restrictions → unauthenticated file read
Requires authenticated session?No — per NVD/Cisco, unauthenticated and remote
AffectedCatalyst SD-WAN Manager: before 20.9.8.2; 20.10–20.12.5.3 (and 20.12.6); 20.13–20.15.4.2; 20.16–20.18.2.1
Fixed in20.9.8.2 · 20.12.5.3 · 20.15.4.2 · 20.18.2.1 (and later)

What you need to know

Insufficient file-system access restrictions let an unauthenticated attacker reach and read sensitive files on the underlying operating system by querying the SD-WAN Manager API. That data is valuable on its own and, in observed attacks, as one link in a chain.

  • It's unauthenticated and API-reachable. No credential is required to pull the exposed data.
  • It's been chained and exploited. Cisco Talos reported widespread exploitation of unpatched SD-WAN Manager infrastructure, with CVE-2026-20133 used alongside CVE-2026-20128 and CVE-2026-20122 to gain access; post-compromise activity included web shells and other tooling.
  • CISA acted on it. It was added to the KEV catalog in April 2026 with a short remediation window.

A note on the details: Cisco and NVD describe this as unauthenticated information disclosure via the API, which is the authoritative reading we follow here.

How serious we see it

High. Taken in isolation, reading files is a confidentiality issue — no code execution, no direct write. We land at High rather than Moderate because the context is unforgiving: it's in CISA's KEV catalog, it's been exploited in the wild, and it's been used as part of a chain that ends in device access on a platform that manages your entire SD-WAN fabric. Cisco's own 6.5 and NVD's 7.5 bracket the paper severity; the KEV listing and active chaining are why we prioritize it above the number. The reassuring, bounded part is that specific versions are affected and fixes are published — no workarounds, but a clear upgrade path.

Recommendations

Straight from Cisco's advisory and CISA:

  1. Patch now. Upgrade to 20.9.8.2 / 20.12.5.3 / 20.15.4.2 / 20.18.2.1 or later. Cisco notes there are no workarounds — remediation is the upgrade.
  2. Hunt for prior use. Given active exploitation, review SD-WAN Manager access and proxy logs for suspicious API activity and for web shells or other implants.
  3. If compromised, respond fully. Rebuild as needed and rotate credentials and secrets reachable from the manager.
  4. Restrict and audit access. Confine API and web-UI access to trusted management ranges, and audit read-only and administrative API accounts.
  5. Confirm your exposure first. Verify whether you run an affected SD-WAN Manager build and how reachable it is.

How BreachRisk sees it

BreachRisk discovers internet-facing Cisco Catalyst SD-WAN Manager in your external footprint, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV. We detect and flag the exposed, affected version; we don't exploit it.

When a management platform for your whole SD-WAN fabric is exposed and under active exploitation, the outside-in view means it's already mapped and ranked — you go straight to patch-and-verify.

References

See your cyber risk, proven.