Junglewise Threat Intelligence

CVE-2026-20224: Cisco Catalyst SD-WAN Manager XXE in web UI

CVE-2026-20224 · Severity: high · CVSS 8.6 · Published 2026-05-14

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager, a centralized management platform for corporate wide-area networks, contains a security flaw in its web interface. An unauthorized attacker can exploit this to remotely read sensitive files from the system without needing a username or password. This could lead to the exposure of configuration data or other confidential information, potentially compromising the security of the entire network infrastructure.

Technical details

An XML External Entity (XXE) vulnerability exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage). The flaw is caused by improper handling of XXE entries when the system parses XML files. A remote, unauthenticated attacker can exploit this by sending a specially crafted XML request to the affected system's web interface. Successful exploitation allows the attacker to read arbitrary files from the underlying filesystem, potentially leading to information disclosure. Cisco has released software updates to address this vulnerability; administrators should refer to the vendor advisory for specific fixed versions across the various release branches.

Affected products

  • Cisco Catalyst SD-WAN Manager < 20.9.9.1, 20.10 < 20.12.5.4, 20.12.6 < 20.12.6.2, 20.12.7, 20.13 < 20.15.4.4, 20.15.5 < 20.15.5.2, 20.16 < 20.18.2.2, 26.1 < 26.1.1.1

Timeline

  • 2026-05-14: advisory: Initial publication of the vulnerability by Cisco.

References

Related threats