Cisco Vulnerabilities and Affected Products
Vulnerabilities associated with Cisco Catalyst SD-WAN Manager.
Products
Clear product- Cisco Small Business RV Series Router Firmware262 vulnerabilities
- Cisco IOS XE Software248 vulnerabilities
- Cisco Firepower Threat Defense Software161 vulnerabilities
- Cisco Adaptive Security Appliance (ASA) Software160 vulnerabilities
- Cisco Identity Services Engine Software156 vulnerabilities
- Cisco Firepower Management Center128 vulnerabilities
- Cisco IOS XR Software107 vulnerabilities
- Cisco NX-OS Software88 vulnerabilities
- Cisco Data Center Network Manager74 vulnerabilities
- Cisco SD-WAN vManage61 vulnerabilities
- Cisco SD-WAN Solution54 vulnerabilities
- Cisco Unified Communications Manager52 vulnerabilities
- Cisco Prime Infrastructure50 vulnerabilities
- Cisco Secure Firewall Threat Defense (FTD) Software48 vulnerabilities
- Cisco Webex Meetings46 vulnerabilities
- Cisco Catalyst SD-WAN Manager45 vulnerabilities
- IOS41 vulnerabilities
- Cisco Enterprise NFV Infrastructure Software39 vulnerabilities
- Cisco IOS36 vulnerabilities
- Cisco Unified Contact Center Express36 vulnerabilities
- Cisco WebEx WRF Player35 vulnerabilities
- Cisco Digital Network Architecture Center (DNA Center)33 vulnerabilities
- Cisco Unified Computing System (Managed)33 vulnerabilities
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software31 vulnerabilities
- Cisco Unity Connection31 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-20313HIGH | Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption VulnerabilitiesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284. CWE-1284Aug 5, 2026 | CVSS7.7v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20312HIGH | Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure VulnerabilitiesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312. CWE-312Aug 5, 2026 | CVSS8.8v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20310CRITICAL | Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File AccessAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. CWE-59Aug 5, 2026 | CVSS9.1v3.1 | EPSS0.369% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20303CRITICAL | Cisco Catalyst SD-WAN Security Hardening Release - Input Validation VulnerabilitiesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. CWE-20Aug 5, 2026 | CVSS9.9v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20294MEDIUM | Cisco Catalyst SD-WAN Manager Information Disclosure VulnerabilityA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit co… CWE-319Aug 5, 2026 | CVSS6.5v3.1 | EPSS0.134% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20304CRITICAL | Cisco Catalyst SD-WAN Security Hardening Release - Access Control VulnerabilitiesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. CWE-284Aug 5, 2026 | CVSS9.9v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20262MEDIUM | Cisco Catalyst SD-WAN Manager Arbitrary File Write VulnerabilityA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful explo… CWE-22Jun 15, 2026 | CVSS6.5v3.1 | EPSS28.2% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20245HIGH | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation VulnerabilityA vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the a… CWE-116Jun 4, 2026 | CVSS7.8v3.1 | EPSS25.3% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20224HIGH | Cisco Catalyst SD-WAN Manager XML External Entity Injection VulnerabilityA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allo… CWE-20May 14, 2026 | CVSS8.6v3.1 | EPSS1.04% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20210MEDIUM | Cisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A success… CWE-779May 14, 2026 | CVSS5.4v3.1 | EPSS0.194% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20209MEDIUM | Cisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged use… CWE-779May 14, 2026 | CVSS5.4v3.1 | EPSS0.194% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20182CRITICAL | Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityMay 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, f… | CVSS10.0v3.1 | EPSS91.5% | PoCs5 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-20108MEDIUM | Generated title:Cisco Catalyst SD-WAN Manager Web-Based Management Interface Cross-Site Scripting VulnerabilityA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrar… CWE-79Mar 25, 2026 | CVSS5.4v3.1 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20122MEDIUM | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite VulnerabilityA vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful expl… CWE-648Feb 25, 2026 | CVSS5.4v3.1 | EPSS24.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20127CRITICAL | Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityA vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could explo… CWE-287Feb 25, 2026 | CVSS10.0v3.1 | EPSS88.2% | PoCs10 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20128HIGH | Cisco Catalyst SD-WAN Manager Information Disclosure VulnerabilityA vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker… CWE-257Feb 25, 2026 | CVSS7.5v3.1 | EPSS6.94% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20129CRITICAL | Cisco Catayst SD-WAN Authentication Bypass VulnerabilityA vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of th… CWE-287Feb 25, 2026 | CVSS9.8v3.1 | EPSS0.717% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20126HIGH | Cisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityA vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system. CWE-648Feb 25, 2026 | CVSS8.8v3.1 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20133MEDIUM | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityA vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system. CWE-200Feb 25, 2026 | CVSS6.5v3.1 | EPSS31.4% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20147MEDIUM | Cisco SD-WAN vManage Stored Cross-Site Scripting VulnerabilityA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacke… CWE-79May 7, 2025 | CVSS5.4v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20216MEDIUM | Cisco Catalyst SD-WAN Manager Reflected HTML Injection VulnerabilityA vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit this vulnerability by convincing an authenticated user to click a malicious link. A successful exploit could allow the attacker to inject HTML into the browser of an authenticated C… CWE-74May 7, 2025 | CVSS4.7v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20187MEDIUM | Cisco SD-WAN Manager Software Arbitrary File Creation VulnerabilityA vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to a… CWE-22May 7, 2025 | CVSS6.5v3.1 | EPSS1.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20122HIGH | Cisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityA vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to ga… CWE-300May 7, 2025 | CVSS7.8v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20213MEDIUM | Cisco Catalyst SDWAN Manager Arbitrary File Overwrite VulnerabilityA vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker must have valid read-only credentials with CLI access on the affected system. This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by running a serie… CWE-78May 7, 2025 | CVSS5.5v3.1 | EPSS0.159% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-20157MEDIUM | Cisco Catalyst vManage Certificate Validation VulnerabilityA vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation of certificates that are used by the Smart Licensing feature. An attacker with a privileged network position could exploit this vulnerability by intercepting traffic that is sent over the Internet. A successful exploit could allow the attack… CWE-295May 7, 2025 | CVSS5.9v3.1 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |