A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Is CVE-2026-20133 exploited?
Listed in the CISA KEV catalog on 2026-04-20.
Federal remediation due 2026-04-23.
Past that date by 114 days.
EPSS puts exploitation in the next 30 days at 31%.
Public exploit code: none found in monitored sources.