CVE-2026-20133
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: a vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive… EPSS 31% (98th percentile).
CISA federal remediation date Apr 23
Vulnerabilities · 147 days ago
CISA’s latest KEV update says defenders cannot wait for vendor confirmation before treating a flaw as live attack surface. The unusual part is CVE-2026-20133: CISA added it to the exploited list even though Cisco has not yet flagged it, which suggests exploitation may be happening before the vendor has fully acknowledged it.
The batch covers eight flaws across Cisco Catalyst SD-WAN Manager, Kentico Xperience, Zimbra Collaboration Suite, PaperCut NG/MF, JetBrains TeamCity, and Quest KACE Systems Management Appliances. The Kentico issue, CVE-2025-2749, affects Xperience 13.0.178 and earlier and can let an attacker execute content on the server remotely; CISA also says the Zimbra, PaperCut, TeamCity, and KACE issues have been used in attacks.
For practitioners, the forward risk is not just the known exploited set. A KEV entry that arrives before the vendor’s exploitation notice is a warning that some activity may still be hidden, especially around Cisco SD-WAN where confirmed attacks already exist.
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: a vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive… EPSS 31% (98th percentile).
CISA federal remediation date Apr 23
Known exploited · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).
CISA federal remediation date May 4
5 sources covering this story
CISA added Cisco Catalyst SD-WAN Manager vulnerability (CVE-2026-20133) to its KEV catalog, Cisco has yet to flag it as exploited.
Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities
CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before.
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
CISA adds six exploited vulnerabilities, including Fortinet and Exchange flaws, requiring FCEB patching by April 27, 2026.
CISA adds second critical flaw in Ivanti EPMM to exploited vulnerabilities catalog
The code injection flaw is similar to a prior vulnerability that was immediately flagged in January.
CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday
government agencies four days to secure their systems against a critical-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in attacks since January.
Part of the PlainSec briefing for 2026-04-21