Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20133

84
FAUCET Score

CVE-2026-20133 describes a sensitive information disclosure vulnerability in Cisco Catalyst SD-WAN Manager, stemming from insufficient file system access restrictions. An unauthenticated, remote attacker can exploit this by accessing the system's API to read sensitive data from the underlying operating system. Rated 7.5 HIGH on CVSS, this vulnerability has a low attack complexity and requires no user interaction, but only impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 20.9.8.2CPE matchmatch criteria
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
>= 20.10, < 20.12.5.3CPE matchmatch criteria
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
>= 20.13, < 20.15.4.2CPE matchmatch criteria
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
>= 20.16, < 20.18.2.1CPE matchmatch criteria
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
20.12.6CPE matchmatch criteria
cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
31.35%
Probability of exploitation in next 30 days
EPSS Percentile
98.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Apr 20, 2026
This CVE's current EPSS score of 0.3135 is in the 97th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

gcppatch availablevia llm_extracted
Fixed in: 1.2
View patch
opensipspatch availablevia llm_extracted
Fixed in: 1.2
View patch
amazonvendor investigatingvia llm_extracted
ciscovendor investigatingvia nvd_reference
View patch
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (8)

opensipsllm-opensips-bf4778697c828122CRITICAL

Cisco Catalyst SD-WAN Vulnerabilities

Mar 18, 2026
amazonllm-amazon-55b3d2bba14e4fedHIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
nutanixllm-nutanix-9cdcf9fbfd6af64aHIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
horillallm-horilla-6fb3f3c3e6362164HIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
leantimellm-leantime-61504359a3f07427HIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
jitsillm-jitsi-995d69ad5b8a8722HIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
inveniosoftwarellm-inveniosoftware-8f1bec2f4239ee80HIGH

Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)

Mar 17, 2026
gcpllm-gcp-582ab54c9a587fb8CRITICAL

Cisco Catalyst SD-WAN Vulnerabilities

Feb 25, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
Vendor Advisory