LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20133 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of Apr 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability tracked as CVE-2026-20133. The flaw falls under CWE-200 and could allow remote attackers to view sensitive information on affected systems.

This matters for organizations that rely on the product to manage wide-area networks, because unauthorized disclosure of configuration or operational data can expand an attacker’s view of the environment without requiring authentication.

How it works

CWE-200 describes a weakness in which sensitive data is made accessible to actors who should not receive it. In this product class the exposure occurs when the application returns information in responses or through interfaces that lack proper access controls.

An attacker who can reach the affected component may retrieve the exposed data directly. No further details on the precise request or response pattern are provided in the available record, so the exact mechanics must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Cisco Catalyst SD-WAN Manager is the centralized management plane for SD-WAN deployments and typically runs in data-center or cloud-hosted instances that administrators reach over the network.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation step.

After patching, review and tighten access controls on all management interfaces, restrict network reachability to only trusted administrative networks, and disable any unnecessary data-exposure features for this class of product.

If you can't patch immediately

Follow the actions required by CISA Emergency Directive 26-03 and the associated Hunt & Hardening Guidance for Cisco SD-WAN devices. Apply network segmentation so that only authorized management hosts can reach the SD-WAN Manager.

If your data may have been exposed

Exposure of sensitive information through this class of vulnerability can contribute to later breaches. Organizations can run a free exposure scan of their email addresses against known breach data to check for signs of prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Manager
WeaknessCWE-200
Added to CISA KEVApr 20, 2026
Federal patch deadlineApr 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities