Skip to content
COOEY

EXPOSURES › CVE-2026-20133

CVE-2026-20133

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-20133 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wilddata-breachunpatched

Cisco Catalyst SD-WAN Manager allows remote attackers to view sensitive information due to an exposure vulnerability actively exploited in the wild.

This vulnerability exposes sensitive data to unauthorized remote actors, creating a significant data breach risk for DIB organizations relying on Cisco SD-WAN infrastructure. While not an RCE, the active exploitation status and sensitivity of exposed information warrant immediate patching and network segmentation to prevent data leakage.

Shame score — The vulnerability allows unauthorized access to sensitive information rather than full system compromise, and while actively exploited, it does not involve default credentials or known negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized