« Back to list

Cisco

Cisco Catalyst Sd-wan Manager: vulnerabilities and CVEs

Cisco Catalyst Sd-wan Manager has 93 published vulnerabilities, 15 of them in the last 12 months. 10 are rated critical and 9 are listed by CISA as actively exploited.

CVEs93
Last 12 months15
Critical10
Actively exploited9

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76504Critical (9.8)1.1%⚠ Active exploitationSep 30, 2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This…
CVE-2026-20262Medium (6.5)28%⚠ Active exploitationJun 15, 2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This…
CVE-2026-20245High (7.8)25%⚠ Active exploitationJun 4, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an…
CVE-2026-20182Critical (10)92%⚠ Active exploitationMay 14, 2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…
CVE-2026-20133High (7.5)32%⚠ Active exploitationFeb 25, 2026
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions.…
CVE-2026-20122Medium (5.4)25%⚠ Active exploitationFeb 25, 2026
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have…
CVE-2026-20128High (7.5)7.1%⚠ Active exploitationFeb 25, 2026
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to…
CVE-2026-20127Critical (10)88%⚠ Active exploitationFeb 25, 2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…
CVE-2022-20775High (7.8)12%⚠ Active exploitationSep 30, 2022
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI.…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76504Critical (9.8)1.1%⚠ Active exploitationSep 30, 2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This…
CVE-2026-20294Medium (6.5)0.13%—Aug 5, 2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability…
CVE-2026-20262Medium (6.5)28%⚠ Active exploitationJun 15, 2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This…
CVE-2026-20245High (7.8)25%⚠ Active exploitationJun 4, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an…
CVE-2026-20224High (8.6)1.0%—May 14, 2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does…
CVE-2026-20210Medium (5.4)0.19%—May 14, 2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions…
CVE-2026-20209Medium (5.4)0.19%—May 14, 2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform…
CVE-2026-20182Critical (10)92%⚠ Active exploitationMay 14, 2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…
CVE-2026-20108Medium (5.4)0.16%—Mar 25, 2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an…
CVE-2026-20133High (7.5)32%⚠ Active exploitationFeb 25, 2026
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions.…
CVE-2026-20129Critical (9.8)0.74%—Feb 25, 2026
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
CVE-2026-20128High (7.5)7.1%⚠ Active exploitationFeb 25, 2026
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to…
CVE-2026-20127Critical (10)88%⚠ Active exploitationFeb 25, 2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…
CVE-2026-20126High (7.8)0.31%—Feb 25, 2026
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient…
CVE-2026-20122Medium (5.4)25%⚠ Active exploitationFeb 25, 2026
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have…
CVE-2025-20216Medium (4.3)0.33%—May 7, 2025
A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This…
CVE-2025-20213Medium (5.5)0.16%—May 7, 2025
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To…
CVE-2025-20187Medium (6.5)1.3%—May 7, 2025
A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This…
CVE-2025-20157Medium (5.9)0.28%—May 7, 2025
A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This…
CVE-2025-20147Medium (5.4)0.32%—May 7, 2025
This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful…
CVE-2025-20122High (7.8)0.15%—May 7, 2025
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This…
CVE-2020-26066Medium (6.5)0.59%—Nov 18, 2024
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is…
CVE-2021-1465Medium (4.3)1.2%—Nov 18, 2024
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on…
CVE-2021-1462Medium (6.7)0.16%—Nov 18, 2024
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this vulnerability, an attacker would need to have a…
CVE-2021-1234Medium (5.3)0.78%—Nov 18, 2024
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this…
CVE-2021-1232Medium (6.5)1.1%—Nov 18, 2024
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of an affected system. This…
CVE-2020-26074High (7.8)0.18%—Nov 18, 2024
A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is…
CVE-2020-26073High (7.5)13%—Nov 18, 2024
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper…
CVE-2020-26071High (8.4)0.19%—Nov 18, 2024
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS)…
CVE-2021-1491Medium (6.5)1.3%—Nov 15, 2024
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This…

📰 Related news

Other products by Cisco