CVE-2026-20133

medium Cisco ⚠️ CISA KEV — Exploited in the Wild
CVSS v3 Base Score
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.4%
Exploitation probability in 30 days
Top 20% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: February 25, 2026 (77 days ago)
Last Modified: April 22, 2026
Vendor: Cisco
Source: NVD

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2026-04-20
Remediation Due: 2026-04-23 (⚠ 21d overdue)

Description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

CWE

CWE-200

Affected Products

cisco catalyst sd-wan manager

References