Synced 16 Jun 2026 15:24 UTC Account
← All products

CVE-2026-20133

MEDIUM severity · CVSS 6.5 · Information disclosure · actively exploited (CISA KEV)
6.5CVSS MEDIUM exploited
Actively exploited in the wild (CISA Known Exploited Vulnerabilities). Added to KEV 2026-04-20. US federal agencies must patch by 2026-04-23.

Summary

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)9%

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products we track (1)

Recommendation

This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.