Cisco
Cisco Catalyst Sd-wan Manager: vulnerabilities and CVEs
Cisco Catalyst Sd-wan Manager has 93 published vulnerabilities, 15 of them in the last 12 months. 10 are rated critical and 9 are listed by CISA as actively exploited.
CVEs93
Last 12 months15
Critical10
Actively exploited9
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76504 | Critical (9.8) | 1.1% | ⚠ Active exploitation | Sep 30, 2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This… |
| CVE-2026-20262 | Medium (6.5) | 28% | ⚠ Active exploitation | Jun 15, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This… |
| CVE-2026-20245 | High (7.8) | 25% | ⚠ Active exploitation | Jun 4, 2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an… |
| CVE-2026-20182 | Critical (10) | 92% | ⚠ Active exploitation | May 14, 2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN… |
| CVE-2026-20133 | High (7.5) | 32% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions.… |
| CVE-2026-20122 | Medium (5.4) | 25% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have… |
| CVE-2026-20128 | High (7.5) | 7.1% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to… |
| CVE-2026-20127 | Critical (10) | 88% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN… |
| CVE-2022-20775 | High (7.8) | 12% | ⚠ Active exploitation | Sep 30, 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI.… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76504 | Critical (9.8) | 1.1% | ⚠ Active exploitation | Sep 30, 2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This… |
| CVE-2026-20294 | Medium (6.5) | 0.13% | — | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability… |
| CVE-2026-20262 | Medium (6.5) | 28% | ⚠ Active exploitation | Jun 15, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This… |
| CVE-2026-20245 | High (7.8) | 25% | ⚠ Active exploitation | Jun 4, 2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an… |
| CVE-2026-20224 | High (8.6) | 1.0% | — | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does… |
| CVE-2026-20210 | Medium (5.4) | 0.19% | — | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions… |
| CVE-2026-20209 | Medium (5.4) | 0.19% | — | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform… |
| CVE-2026-20182 | Critical (10) | 92% | ⚠ Active exploitation | May 14, 2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN… |
| CVE-2026-20108 | Medium (5.4) | 0.16% | — | Mar 25, 2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an… |
| CVE-2026-20133 | High (7.5) | 32% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions.… |
| CVE-2026-20129 | Critical (9.8) | 0.74% | — | Feb 25, 2026 | A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. |
| CVE-2026-20128 | High (7.5) | 7.1% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to… |
| CVE-2026-20127 | Critical (10) | 88% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN… |
| CVE-2026-20126 | High (7.8) | 0.31% | — | Feb 25, 2026 | A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient… |
| CVE-2026-20122 | Medium (5.4) | 25% | ⚠ Active exploitation | Feb 25, 2026 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have… |
| CVE-2025-20216 | Medium (4.3) | 0.33% | — | May 7, 2025 | A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This… |
| CVE-2025-20213 | Medium (5.5) | 0.16% | — | May 7, 2025 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To… |
| CVE-2025-20187 | Medium (6.5) | 1.3% | — | May 7, 2025 | A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This… |
| CVE-2025-20157 | Medium (5.9) | 0.28% | — | May 7, 2025 | A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This… |
| CVE-2025-20147 | Medium (5.4) | 0.32% | — | May 7, 2025 | This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful… |
| CVE-2025-20122 | High (7.8) | 0.15% | — | May 7, 2025 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This… |
| CVE-2020-26066 | Medium (6.5) | 0.59% | — | Nov 18, 2024 | A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is… |
| CVE-2021-1465 | Medium (4.3) | 1.2% | — | Nov 18, 2024 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on… |
| CVE-2021-1462 | Medium (6.7) | 0.16% | — | Nov 18, 2024 | A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this vulnerability, an attacker would need to have a… |
| CVE-2021-1234 | Medium (5.3) | 0.78% | — | Nov 18, 2024 | A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this… |
| CVE-2021-1232 | Medium (6.5) | 1.1% | — | Nov 18, 2024 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of an affected system. This… |
| CVE-2020-26074 | High (7.8) | 0.18% | — | Nov 18, 2024 | A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is… |
| CVE-2020-26073 | High (7.5) | 13% | — | Nov 18, 2024 | A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper… |
| CVE-2020-26071 | High (8.4) | 0.19% | — | Nov 18, 2024 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS)… |
| CVE-2021-1491 | Medium (6.5) | 1.3% | — | Nov 15, 2024 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This… |