CVE-2026-20133

MEDIUM(6.5)KEVElevated Risk

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Description

CVE-2026-20133 is a HIGH severity information disclosure vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage), classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability allows remote attackers to view sensitive information on affected systems without requiring physical access or additional authentication beyond network reachability to the management interface. Cisco SD-WAN Manager is the centralized control plane for enterprise SD-WAN deployments, managing routing policy, device configurations, VPN credentials, and authentication data for potentially hundreds of connected branch routers — making any unauthorized information exposure highly consequential. CISA added CVE-2026-20133 to the Known Exploited Vulnerabilities (KEV) catalog on April 20, 2026, and included it under Emergency Directive 26-03, which mandates federal agency remediation by April 23, 2026. CVE-2026-20133 is one of three SD-WAN Manager vulnerabilities covered by ED 26-03, alongside CVE-2026-20122 and CVE-2026-20128; in a chained attack scenario, information disclosed via this CVE (such as credentials or session tokens) can directly enable exploitation of the privilege escalation flaw in CVE-2026-20122. The EPSS score is 0.0139, placing the vulnerability at the 80.4th percentile — indicating it ranks in the top fifth of all CVEs by predicted exploitation likelihood.

KEV Information

Vendor
Cisco
Product
Catalyst SD-WAN Manager
Date Added
April 20, 2026
Due Date
April 23, 2026
Required Action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
ciscocatalyst sd-wan manager< 20.9.8.2; >= 20.10, < 20.12.5.3; >= 20.13, < 20.15.4.2; >= 20.16, < 20.18.2.1; 20.12.6

Multiple CVSS Assessments

Source: [email protected](Secondary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Source: [email protected](Primary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Weakness Type

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CWE-200 covers scenarios in which software inadvertently exposes information to actors who are not authorized to receive it. This may occur through improper access controls on API endpoints or web interfaces, overly verbose error messages that leak internal state, debug or diagnostic endpoints left exposed in production, or responses that include data beyond what the requester is authorized to view. In network management platforms, the consequences of CWE-200 are amplified because the sensitive information managed by these systems — credentials, encryption keys, VPN configurations, device certificates — forms the trust fabric for an entire network.

In CVE-2026-20133, the information exposure affects Cisco SD-WAN Manager's management interface and is reachable by remote attackers. The precise mechanism — whether an unauthenticated API endpoint, insufficient authorization scoping, or response data leakage — is described in Cisco's security advisory. Regardless of the exact code path, the consequence is that an attacker with network access to the SD-WAN Manager can retrieve sensitive operational data, which in the context of the broader ED 26-03 cluster likely includes material useful for escalating to full SD-WAN fabric compromise via CVE-2026-20122. Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Impact Analysis

No official NVD CVSS score has been published for CVE-2026-20133 at time of writing. The following assessment is based on the vulnerability's technical characteristics, its classification under CISA Emergency Directive 26-03, and its role within the three-CVE SD-WAN Manager attack cluster.

Attack Vector (Network): The vulnerability is exploitable remotely over the network. The SD-WAN Manager management interface is accessible over HTTPS and, in many enterprise deployments, is reachable from administrative networks or directly from the internet if not properly firewalled.

Attack Complexity (Low): Information disclosure vulnerabilities in management interfaces typically require no special pre-conditions beyond network connectivity and, in some cases, valid credentials. The 80.4th percentile EPSS score suggests the community assesses exploitation as straightforward.

Privileges Required (Unknown): The exact authentication requirement is not confirmed in public disclosures at the time of writing. Given the description of "remote attackers" (without qualification), the vulnerability may be exploitable without authentication, which would substantially elevate risk.

Confidentiality Impact (High): SD-WAN Manager stores and processes exceptionally sensitive data: device credentials, TLS certificates, VPN pre-shared keys, routing policies, and potentially administrator account data. Unauthorized access to this information can enable full SD-WAN fabric takeover.

Integrity and Availability: Indirect impact — information disclosed may be leveraged to enable configuration changes or service disruption via subsequent attacks, particularly CVE-2026-20122.

Prioritization Guidance: The 80.4th percentile EPSS, KEV listing, Emergency Directive 26-03 with a three-day deadline, and its role as a reconnaissance enabler for the privilege-escalation cluster make CVE-2026-20133 a critical remediation priority for all Cisco SD-WAN Manager operators.

Exploit Maturity

KEV and Emergency Directive: CVE-2026-20133 was added to CISA's Known Exploited Vulnerabilities catalog on April 20, 2026, as part of Emergency Directive 26-03. The Emergency Directive classification — CISA's highest-urgency response mechanism for vulnerabilities with confirmed exploitation against federal infrastructure — confirms that active exploitation is occurring and that the threat is considered imminent and severe.

EPSS Context: An EPSS score of 0.0139 (80.4th percentile) places CVE-2026-20133 in the top 20% of all CVEs by predicted exploitation probability. For a newly disclosed vulnerability in critical network infrastructure, this percentile ranking reflects significant attacker interest and the perceived ease of exploitation.

Multi-CVE Exploitation Cluster: CVE-2026-20133 is most dangerous when used in combination with CVE-2026-20122. The information disclosure capability can function as a reconnaissance step — harvesting credentials or session tokens — that enables the privilege escalation in CVE-2026-20122. Sophisticated threat actors targeting Cisco SD-WAN infrastructure would logically chain these vulnerabilities, and CISA's coordinated ED 26-03 response suggests this chaining pattern has been observed.

Ransomware: No ransomware campaigns have been specifically attributed to CVE-2026-20133 at the time of writing. However, the broader class of Cisco SD-WAN Manager compromises has drawn interest from ransomware operators and nation-state actors due to the network-wide blast radius a compromised management plane enables.

Public PoC: No public proof-of-concept code has been confirmed as of April 24, 2026. The short window between KEV listing and the current date makes public PoC availability unlikely but does not reduce operational risk from well-resourced threat actors.

Remediation

  1. Comply with CISA Emergency Directive 26-03. Federal civilian executive branch agencies must remediate CVE-2026-20133 by April 23, 2026. All other organizations operating Cisco Catalyst SD-WAN Manager should adopt this deadline as a best-practice target given confirmed exploitation activity and the vulnerability's role in a multi-stage attack chain.

  2. Apply Cisco security patches immediately. Monitor the Cisco Security Advisory for CVE-2026-20133 (tools.cisco.com/security/center) and deploy the patched SD-WAN Manager software release upon availability. Coordinate patching with CVE-2026-20122 and CVE-2026-20128 remediations, as all three are addressed under the same Emergency Directive.

  3. Isolate the SD-WAN Manager management interface. As an immediate interim mitigation, ensure the SD-WAN Manager's HTTPS management port (typically 8443) is not reachable from untrusted networks. Enforce access exclusively via a dedicated management network segment, VPN, or privileged access workstations (PAWs). Apply network ACLs and firewall rules to restrict source IPs to known administrative hosts.

  4. Rotate potentially disclosed credentials. Assume that any credentials, certificates, or API keys stored or processed by the SD-WAN Manager may have been disclosed. Proactively rotate SD-WAN device credentials, controller certificates, and administrator account passwords as part of the incident response posture until the system is confirmed uncompromised.

  5. Review access logs for unauthorized information retrieval. Examine SD-WAN Manager audit logs and web server access logs for unusual GET requests, API calls returning large data payloads, or access patterns from unexpected source IP addresses. Correlate with SIEM data to identify potential reconnaissance activity preceding a privilege escalation attempt.

  6. Apply defense-in-depth for sensitive data storage. Review which sensitive data is stored in plaintext or with reversible encryption in the SD-WAN Manager database. Apply vendor hardening guides to minimize the sensitivity of data exposed through the management interface, and ensure that secrets management follows the principle of least exposure.

Technical Details

CVE-2026-20133 affects Cisco Catalyst SD-WAN Manager, the centralized management and orchestration platform for Cisco's SD-WAN solution. SD-WAN Manager exposes a web-based management interface and a REST API used by administrators, the SD-WAN controllers (vSmart, vBond), and connected devices for configuration, policy management, and telemetry.

Root Cause — Unauthorized Information Exposure: The vulnerability is rooted in CWE-200: a component of the SD-WAN Manager's interface exposes sensitive information to actors who lack authorization to access it. In network management platforms, this class of vulnerability commonly manifests as: (a) API endpoints that return data without verifying the caller's authorization scope, (b) error responses or debug output that include internal state such as credentials or configuration fragments, or (c) responses that include data fields beyond what the requesting role is entitled to see.

Sensitive Data at Risk: Cisco SD-WAN Manager is a high-value target for information disclosure because it stores and manages the trust material for the entire SD-WAN fabric: device authentication credentials, TLS certificates and private keys for controller-to-device communication, VPN configurations, routing policy definitions, template data that may include plaintext or weakly protected secrets, and administrator account data. Disclosure of any subset of this information can enable an attacker to impersonate devices, intercept encrypted SD-WAN traffic, or pivot to full fabric compromise.

Relationship to CVE-2026-20122: CVE-2026-20133 and CVE-2026-20122 are closely related in an attack chain context. Information disclosed via CVE-2026-20133 — such as valid low-privilege credentials, session tokens, or API keys — can directly satisfy the authentication prerequisite for exploiting CVE-2026-20122's privileged file-upload API. CISA's grouping of both CVEs under a single Emergency Directive reflects this chained exploitation risk.

CVSS Context: No formal CVSS vector has been published. Based on the described attack pattern (remote, low or no authentication required, high confidentiality impact), a contextual CVSS estimate of 7.5–8.6 (HIGH) is appropriate. Vendor advisory confirmation is required for the authoritative score.

Frequently Asked Questions

Is CVE-2026-20133 being actively exploited?

Yes. CISA added CVE-2026-20133 to the KEV catalog on April 20, 2026, under Emergency Directive 26-03, which is issued only for vulnerabilities with confirmed active exploitation posing severe risk to government and critical infrastructure networks. All Cisco SD-WAN Manager operators should treat this as an active threat.

What products are affected?

Cisco Catalyst SD-WAN Manager (formerly vManage) is the affected product. Refer to the Cisco Security Advisory for CVE-2026-20133 for the specific software versions that contain the vulnerability. Downstream SD-WAN components (edge routers, vSmart, vBond) are not directly vulnerable but are at elevated risk if the SD-WAN Manager is compromised and credential material is disclosed.

How do I fix it?

Patch Cisco Catalyst SD-WAN Manager to the fixed version specified in the Cisco Security Advisory. As an immediate interim mitigation, restrict all network access to the SD-WAN Manager management interface to known administrative IP ranges, enforce VPN-based access, and rotate any credentials or certificates stored in SD-WAN Manager as a precaution. Apply all three patches covered by ED 26-03 together.

How severe is it?

CVE-2026-20133 is rated HIGH severity. The combination of remote exploitability, a high-value sensitive-data target (SD-WAN credentials and configuration), the 80.4th percentile EPSS score, and its role as a reconnaissance enabler for the privilege-escalation cluster makes it a critical operational risk for any organization relying on Cisco SD-WAN infrastructure.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score31.35%
EPSS Percentile98.1%

Dates

PublishedFebruary 25, 2026
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.