Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3620 articles · 153652 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-20128KEVEXPLOITEDPATCHED
cis · catalyst_sd-wan_manager

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

Description

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

Affected Products

VendorProductVersions
ciscatalyst_sd-wan_manager20.1.12, 19.2.1, 18.4.4, 18.4.5, 20.1.1.1, 20.1.1, 19.3.0, 19.2.2, 19.2.099, 18.3.6, 18.3.7, 19.2.0, 18.3.8, 19.0.0, 19.1.0, 18.4.302, 18.4.303, 19.2.097, 19.2.098, 17.2.10, 18.3.6.1, 19.0.1a, 18.2.0, 18.4.3, 18.4.1, 17.2.8, 18.3.3.1, 18.4.0, 18.3.1, 17.2.6, 17.2.9, 18.3.4, 17.2.5, 18.3.1.1, 18.3.5, 18.4.0.1, 18.3.3, 17.2.7, 18.3.0, 19.2.3, 18.4.501_ES, 20.3.1, 20.1.2, 19.2.929, 19.2.31, 20.3.2, 19.2.32, 20.3.2.1, 20.3.2.1_927, 18.4.6, 20.3.2_928, 20.3.2_929, 20.4.1.0.1, 20.3.2.1_930, 19.2.4, 20.5.0.1.1, 20.4.1.1, 20.3.3, 19.2.4.0.1, 20.3.2_937, 20.5.1, 20.1.3, 20.3.3.0.4, 20.3.3.1.2, 20.3.3.1.1, 20.4.1.2, 20.3.3.0.2, 20.4.1.1.5, 20.4.1.0.02, 20.3.3.1.7, 20.3.3.1.5, 20.5.1.0.1, 20.3.3.1.10, 20.3.3.0.8, 20.4.2, 20.3.4, 20.3.3.0.14, 19.2.4.0.8, 19.2.4.0.9, 20.3.4.0.1, 20.3.2.0.5, 20.5.1.0.2, 20.6.1.1, 20.6.0.18.3, 20.3.2.0.6, 20.6.0.18.4, 20.4.2.0.2, 20.3.3.0.16, 20.6.1.0.1, 20.3.4.0.6, 20.7.1EFT2, 20.3.4.0.9, 20.3.4.0.11, 20.3.3.0.18, 20.6.2.1, 20.3.4.1, 20.4.2.1, 20.4.2.1.1, 20.3.4.1.1, 20.3.813, 20.3.4.0.19, 20.4.2.2.1, 20.5.1.2, 20.3.814, 20.4.2.2, 20.6.2.2, 20.3.4.2.1, 20.3.4.1.2, 20.3.4.0.20, 20.6.2.2.3, 20.4.2.2.2, 20.6.2.0.4, 20.3.4.0.24, 20.6.2.2.7, 20.3.4.2.2, 20.4.2.2.4, 20.3.5.0.8, 20.3.5.0.9, 20.3.5.0.7, 20.6.3.0.2, 20.9.1EFT2, 20.3.6, 20.3.7, 20.4.2.3, 20.3.5.1, 20.3.4.3, 20.3.3.2, 20.3.7.1, 20.3.4.0.25, 20.6.2.2.4, 20.6.1.2, 20.1.3.1, 20.6.5.1.4, 20.3.8, 20.12.501, 26.1.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscatalyst sd-wancert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v

Related News (6 articles)

Tier D
SecurityWeek2h ago
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
→ No new info (linked only)
Tier A
Cisco Security22d ago
Cisco Catalyst SD-WAN Vulnerabilities
→ No new info (linked only)
Tier D
BleepingComputer23d ago
CISA flags new SD-WAN flaw as actively exploited in attacks
→ No new info (linked only)
Tier D
Help Net Security23d ago
CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133)
→ No new info (linked only)
Tier B
BSI Advisories24d ago
[UPDATE] [kritisch] Cisco Catalyst SD-WAN Manager und SD-WAN Controller: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CCCS Canada24d ago
Cisco security advisory (AV26-166) – Update 3
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
20.9.8.220.12.5.320.15.4.220.18
CWECWE-257
PublishedFeb 25, 2026
Last enriched23d agov2
Tags
CVE-2026-20133CVE-2026-20128CVE-2026-20122
Trending Score142🔥
Source articles6
Independent6
Info Completeness10/14
Missing: epss, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20182EXPKEV
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Trending: 159
MEDIUMCVE-2026-20122EXPKEV
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
Trending: 138
MEDIUMCVE-2026-20133EXPKEV
CVE-2026-20133: A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive info
Trending: 134
CRITICALCVE-2026-20127EXPKEV
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r
Trending: 122
NONECVE-2026-20188
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory
Trending: 53

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 25, 2026
Added to CISA KEV
Feb 25, 2026
Discovered by ZDM
Apr 1, 2026
Actively Exploited
Apr 21, 2026
Patch Available
Apr 21, 2026
Updated: tags
Apr 21, 2026

Version History

v2
Last enriched 23d ago
v2Tier D23d ago

Marked exploit availability as true and added new CVE tags for related vulnerabilities.

tags
via Help Net Security
v143d ago

Initial creation