CVE-2026-20133: listed in the CISA KEV catalog

CVE-2026-20133 · CVSS 6.5 MEDIUM · EPSS 31% · KEV 2026-04-20

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Is CVE-2026-20133 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-20133

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.