
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20133 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows unauthenticated, remote attackers to read sensitive information on affected systems. The vulnerability was first published on February 25, 2026, and is part of a broader advisory (cisco-sa-sdwan-authbp-qwCX8D4v) covering multiple SD-WAN flaws. Affected versions include releases prior to 20.9.8.2, 20.12.5.3 (or 20.12.6.1), 20.15.4.2, and 20.18.2.1. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, CISA KEV).
The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and stems from insufficient file system access restrictions in the Cisco Catalyst SD-WAN Manager API. An unauthenticated attacker can exploit this flaw by sending crafted HTTP requests to the API endpoint, bypassing access controls to read sensitive files on the underlying operating system — no credentials are required. The Cisco advisory notes the bug ID is CSCws33583, and the flaw was discovered internally by Arthur Vidineyev of Cisco's Advanced Security Initiatives Group (ASIG). Technical analysis from VulnCheck and Decryption Digest indicates this CVE can be chained with companion vulnerabilities (e.g., CVE-2026-20128, CVE-2026-20122) to achieve credential theft and further system compromise (Cisco Advisory, VulnCheck).
Successful exploitation allows an unauthenticated remote attacker to read sensitive files from the underlying operating system of the SD-WAN Manager, potentially exposing credentials, configuration data, and other confidential information. When chained with related vulnerabilities in the same advisory (CVE-2026-20128 for DCA credential theft, CVE-2026-20122 for arbitrary file overwrite, CVE-2026-20129 for authentication bypass), attackers can escalate from information disclosure to full system compromise, including root-level access. The vulnerability has been linked to ransomware-adjacent campaigns and is tracked as exploited in the wild by CISA, with the threat actor group UAT-8616 and the Behinder web shell malware family associated with exploitation activity (CISA KEV, Cisco Advisory).
/opt/data/containers/config/data-collection-agent/.dca exploited in the related CVE-2026-20128)./var/log/nms/containers/service-proxy/serviceproxy-access.log for unexpected unauthenticated GET requests to sensitive API paths; cross-reference source IPs against known administrator addresses./reports/data/opt/data/containers/config/data-collection-agent/.dca from non-administrator IPs, e.g.: "GET /reports/data/opt/data/containers/config/data-collection-agent/.dca HTTP/1.1" 200/dataservice/smartLicensing/uploadAck and check vmanage-server.log for suspicious filenames being written, such as path traversal patterns (e.g., ../../../../../../../../../../../var/lib/wildfly/standalone/deployments/cmd.gz.war)./cmd.gz/cmd.jsp or similar web shell files not present on a clean installation; any access to this endpoint is a confirmed IOC./cmd.gz/cmd.jsp in the service proxy access log: "POST /cmd.gz/cmd.jsp HTTP/1.1" 200python-requests user-agent) from unexpected source IPs.Cisco has released fixed software versions and confirms there are no workarounds available. Organizations should upgrade to the following minimum fixed releases based on their current branch: 20.9.8.2 (for 20.9.x), 20.12.5.3 or 20.12.6.1 (for 20.10–20.12.x), 20.15.4.2 (for 20.13–20.15.x), or 20.18.2.1 (for 20.16–20.18.x). Releases earlier than 20.9 should migrate to a supported fixed release. As hardening measures, Cisco recommends restricting API and management interface access to trusted hosts only, disabling HTTP for the web UI, enabling external log forwarding, and following the Cisco Catalyst SD-WAN Hardening Guide. CISA's Emergency Directive ED-26-03 and supplemental Hunt & Hardening Guidance provide additional federal agency-specific remediation steps (Cisco Advisory, CISA KEV).
Cisco's PSIRT updated the advisory on April 22, 2026 to confirm active exploitation of CVE-2026-20133, having previously (in March 2026) only confirmed exploitation of the companion CVEs (CVE-2026-20128 and CVE-2026-20122). CISA issued Emergency Directive ED-26-03 and added the vulnerability to the KEV catalog with an unusually short three-day federal remediation deadline, signaling high urgency. Tenable published an FAQ on the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities, attributing activity to the threat cluster UAT-8616 and noting over 10 threat groups targeting these flaws (Tenable FAQ). Security media including BleepingComputer, The Register, Cybersecurity Dive, and Help Net Security covered the KEV addition extensively, with commentary noting that security teams may be underestimating the broader threat posed by the SD-WAN vulnerability cluster (Cisco Advisory, VulnCheck).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."