CVE-2026-20133Active Exploitation(cisco / catalyst_sd-wan_manager)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-23. Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • Active exploitation appears in 37 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 54 mentions across 16 observed days

What's happening

  • Active exploitation reported across 37 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 24 signals
  • Disclosure: 7 classified signals
  • General: 5 classified signals
  • Peaked 9d ago at 16 mentions (2026-04-21); latest day: 3
  • 54 total mentions across 16 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline54 mentions / 16d
0481216Mentions · 2026-02-28: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2Mentions · 2026-03-19: 1Mentions · 2026-04-20: 4Mentions · 2026-04-21: 16Mentions · 2026-04-22: 5Mentions · 2026-04-23: 6Mentions · 2026-04-24: 3Mentions · 2026-04-28: 3Mentions · 2026-05-01: 1Mentions · 2026-05-05: 2Mentions · 2026-05-14: 1Mentions · 2026-05-24: 4Mentions · 2026-06-14: 3PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-05-14: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-04-20: 2Active Exploitation · 2026-04-21: 12Active Exploitation · 2026-04-22: 3Active Exploitation · 2026-04-23: 6Active Exploitation · 2026-04-24: 2Active Exploitation · 2026-04-28: 2Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-24: 3Active Exploitation · 2026-06-14: 2Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 3Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 7Technical Details · 2026-04-22: 3Technical Details · 2026-04-23: 3Technical Details · 2026-04-24: 2Technical Details · 2026-04-28: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-24: 2Technical Details · 2026-06-14: 102-2803-1203-1303-1603-1904-2004-2104-2204-2304-2404-2805-0105-0505-1405-2406-14
Signal classification5 categories
Active Exploitation
3768.5%
Disclosure
713.0%
General
59.3%
Patch
35.6%
PoC
23.7%
Referenced assets53 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-281
Disclosure1
2026-03-121
PoC1
2026-03-131
PoC1
2026-03-162
Active Exploitation1General1
2026-03-191
Disclosure1
2026-04-204
Active Exploitation2General1Patch1
2026-04-2116
Active Exploitation12Disclosure2General2
2026-04-225
Active Exploitation3Disclosure2
2026-04-236
Active Exploitation6
2026-04-243
Active Exploitation2Patch1
2026-04-283
Active Exploitation2General1
2026-05-011
Active Exploitation1
2026-05-052
Active Exploitation2
2026-05-141
Active Exploitation1
2026-05-244
Active Exploitation3Patch1
2026-06-143
Active Exploitation2Disclosure1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Cisco warns of active exploitation for CVE-2026-20133 in Catalyst SD-WAN Manager. Unauthenticated attackers can leak OS data. Patch by April 24, 2026. #CiscoSecurity #CVE202620133 #SDWAN #InfoSec #CyberSecurity #CISA #PatchNow https://securityonline.info/cisco-sd-wan-manager-information-disclosure-cve-2026-20133-exploit/ https://t.co/cJAP5iWHxW

    Post summary

    Cisco warns that CVE‑2026‑20133 is actively exploited, enabling unauthenticated attackers to leak OS data, with a patch slated for April 24 2026.

    160146848
    12.5K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    Last month, the VulnCheck research crew thought it was puzzling that Cisco Catalyst SD-WAN CVE-2026-20133 hadn't yet been reported exploited in the wild. Today it was added to CISA KEV and VulnCheck KEV. https://www.vulncheck.com/blog/cisco-sd-wan-manager-vulns

    Post summary

    The post notes that what was once considered unexploited (CVE-2026-20133) has now been listed on CISA and VulnCheck KEV, indicating it is being actively exploited.

    4401221.6K
    3.6K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Cisco Catalyst SD-WAN Vulnerabilities CVE-2026-20122/CVE-2026-20126/CVE-2026-20128/CVE-2026-20129/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 『Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、攻撃者が影響を受けるシステムにアクセスし、root権限に昇格し、機密情報にアクセスして任意のファイルを上書きできる可能性があります。』

    Post summary

    The text announces a set of CVEs affecting Cisco Catalyst SD‑WAN Manager, describing the privilege‑escalation impact but providing no exploit details, PoC, or evidence of active exploitation.

    0301322.3K
    11.7K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    CiscoのSD-WAN管理基盤に、未認証の外部攻撃者が機密情報へアクセスできる重大欠陥が発覚し、すでに実環境で悪用が確認された。 設定に関係なく影響するため、企業ネットワーク全体に深刻なリスクが及んでいる。 CVE-2026-20133はCisco Catalyst SD-WAN Managerに存在する情報漏えい脆弱性で、ファイルシステムのアクセス制御不備に起因する。 攻撃者は認証なしでAPIへアクセスするだけで欠陥を突き、基盤OS上の機密データを読み取ることが可能となる。複雑な侵入手順を必要とせず、外部から直接悪用できる点が特に危険とされる。 Ciscoは設定変更では回避できないと警告しており、2月の公開時点から状況は急変し、4月には実際の攻撃が確認された。CISAも既知悪用脆弱性に追加し、各機関に即時対応を求めている。修正は各バージョンごとに提供されており、20.9系は20.9.8.2、20.10系は20.12.6.1などへの更新が必要である。 https://securityonline.info/cisco-sd-wan-manager-information-disclosure-cve-2026-20133-exploit/

    Post summary

    The post confirms that CVE‑2026‑20133 is actively exploited, provides a PoC link, and lists vendor patches, underscoring the urgency for remediation.

    031921.5K
    14.4K followersView on X
  • Caitlin Condon@catc0n
    PoC

    The @VulnCheckAI team has been herding cats, and by cats, I mean Cisco SD-WAN vulnerabilities. Early public PoC for CVE-2026-20127 was misattributed, and several other vulns are likely flying under the radar (i.e., CVE-2026-20133). https://www.vulncheck.com/blog/cisco-sd-wan-manager-vulns

    Post summary

    The tweet acknowledges the existence of a public PoC for CVE‑2026‑20127 and hints at additional, less-known Cisco SD‑WAN vulnerabilities, but it does not provide exploit code, active exploitation evidence, patches, or technical details.

    120661.2K
    3.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Authentication bypass in Cisco SD-WAN systems exploited by sophisticated threat actors. Multiple CVEs under active attack with webshells, miners, and credential theft campaigns targeting enterprise networks. Key technical details: • CVE-2026-20182: Authentication bypass in SD-WAN Controller/Manager allows admin access. UAT-8616 actor exploits with SSH key injection and privilege escalation (T1078, T1548) • CVE-2026-20133/20128/20122: Vulnerability chain exploited by 10+ threat clusters since March 2026 using ZeroZenX Labs PoC • Post-exploitation: JSP webshells (XenShell, Godzilla, Behinder), XMRig miners, AdaptixC2/Sliver implants, credential harvesting tools • IOCs include C2 servers at 194[.]163[.]175[.]135, 23[.]27[.]143[.]170, and replit[.]dev-hosted backdoors Attack methodology: • Initial access via unauthenticated exploitation of SD-WAN management interfaces • Webshell deployment for persistent access and command execution • Secondary payload delivery: red team frameworks, cryptocurrency miners, network scanning tools • Credential extraction targeting admin hashdumps, JWT tokens, and AWS keys from vManage Hunt for JSP files in SD-WAN web directories with recent timestamps, monitor for XMRig processes, and check for SSH key additions to authorized_keys. Snort SIDs 66482-66483 detect CVE-2026-20182 exploitation. #DFIR_Radar

    Post summary

    CVE‑2026‑20182 and related CVEs in Cisco SD‑WAN are actively exploited by threat actors using webshells, miners, and credential theft tactics, with ZeroZenX Labs PoC releases and Snort SIDs for detection.

    21141623
    1.8K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133) https://www.helpnetsecurity.com/2026/04/21/cisa-flags-another-cisco-catalyst-sd-wan-manager-bug-as-exploited-cve-2026-20133/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA confirms that CVE-2026-20133 is being actively exploited in the wild, but the post contains no exploit code, patch information, or technical vulnerability details.

    02040436
    194.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/20追加) 🛡️No.1571 CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability ✅概要 ・深刻度:重要 7.1 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:特権 API の不適切な使用 (CWE-648) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の API において、認証されたリモートの攻撃者がローカルファイルシステム上の任意のファイルを上書きできる脆弱性。悪用には影響を受けるシステムに対する API アクセス権を持つ有効な読み取り専用資格情報が必要。事前認証されていない攻撃者により、任意ファイルの上書きに加え、vmanage ユーザー権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・攻撃者が API アクセス権を持つ有効な読み取り専用資格情報を有していること。 ________________________________________ ✅悪用時影響 ・ローカルファイルシステム上の任意のファイルを上書き ・vmanage ユーザー権限を取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20122 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems 🛡️No.1572 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:情報漏えい (CWE-200) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager において、事前認証されていない攻撃者により、機密情報を摂取される恐れがある。原因はファイルシステムのアクセス制限が不十分なためで、攻撃者は対象システムのAPIにアクセスして悪用。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・該当システム上の機密情報を閲覧 ・基盤となるオペレーティングシステム上の機密情報を読み取られる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 🛡️No.1573 CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / VulnCheck (CNA) ・種別:パス・トラバーサル、 危険なタイプのファイルの無制限アップロード(CWE-22,CWE-434) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) Kentico Xperience 13.0.178以前に、認証済の攻撃者によって、Staging Sync Server経由で任意の相対パスへデータをアップロード可能な脆弱性が存在。パストラバーサルと任意ファイルアップロードを経てサーバサイドで実行可能なコンテンツ配置によるリモートコード実行を行われる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Kentico Xperience 13.0.177以前が稼働していること。 ・Staging Serviceが有効であること。 ・Staging Serviceがユーザー名/パスワード認証で構成されていること。 ・攻撃者がStaging Sync Serverに対する有効な認証済み権限を有すること。 ________________________________________ ✅悪用時影響 ・任意ファイルアップロードにより、サーバサイドで実行可能なコンテンツを配置 ・リモートコードの実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-2749 https://devnet.kentico.com/download/hotfixes 🛡️No.1574 CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / NVD ・種別:不適切な認証 (CWE-287) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N PaperCut NG/MFのApplication Serverにおいて、事前認証されていない攻撃者により、リモートからユーザー情報を取得される恐れがある。対象となる情報に、PaperCutは、ユーザー名、氏名、メールアドレス、部署情報、カード番号に加え、内部作成ユーザーのハッシュ化パスワードを取得され得ると報告。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・PaperCut NG/MFのApplication Serverが脆弱バージョンで稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証を回避して、ユーザー名、氏名、メールアドレス、部署情報、カード番号などのユーザー情報を取得 ・内部作成ユーザーに限り、ハッシュ化されたパスワードを取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず (GitHub) ・ITW:未確認 (PaperCut) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-27351 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 🛡️No.1575 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability ✅概要 ・深刻度:注意6.1 (CVSS Base) / CISA-ADP ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の Classic UI において、HTMLコンテンツの不十分なサニタイズにより、ユーザーのセッション内で任意のJavaScriptを実行される恐れがある。細工されたタグ構造や属性値に含まれる @ import ディレクティブなどのスクリプト注入ベクトルが原因。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の脆弱バージョンが稼働していること。 ・攻撃者が細工した電子メールメッセージを対象ユーザーに閲覧させること。 ・Classic UI で細工された電子メールメッセージが閲覧されること。 ・追加の利用者操作は不要。 ________________________________________ ✅悪用時影響 ・ユーザーのセッション内で任意のJavaScriptを実行 ・機微情報への不正アクセスにつながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-48700 https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories 🛡️No.1576 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:復元可能な形式でのパスワード保存 (CWE-257) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の Data Collection Agent(DCA)機能において、事前認証されていない攻撃者により、リモートから DCA ユーザー権限を取得される恐れがある。影響を受けるシステム上に DCA ユーザーの認証情報ファイルが存在することで、細工された HTTP 要求により当該ファイルを読み取られる可能性。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・DCA パスワードを含むファイルを読み取られる ・別の影響を受けるシステムへアクセスされ、DCA ユーザー権限を取得される ・機密情報へアクセスされる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20128 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v   🛡️No.1577 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Quest KACE Systems Management Appliance (SMA) には、事前認証されていない攻撃者により、正規ユーザーになりすませる認証回避の脆弱性が存在。SSO認証処理に起因し他脆弱性で、完全な管理者乗っ取りをされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Quest KACE Systems Management Appliance (SMA) の脆弱バージョンが稼働していること。 ・対象機器がネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・正当な認証情報なしに正規ユーザーになりすまされる ・完全な管理者権限を取得される ・アプライアンスを全面的に掌握される ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Arctic Wolf は、2026年3月9日の週から、インターネット公開された未パッチのKACE SMAに対するCVE-2025-32975悪用の可能性がある不正活動を顧客環境で観測したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32975 https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 🛡️No.1578 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.3 (CVSS Base) / JetBrains s.r.o. (CNA) (NVD) ・種別:相対パストラバーサル (CWE-23) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (NVD) JetBrains TeamCity 2023.11.4未満に相対パストラバーサルの脆弱性が存在。事前認証されていない攻撃者により、HTTP(S)経由で認証チェックを回避し、TeamCityサーバの管理権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・TeamCity On-Premises 2023.11.3以前が稼働していること。 ・攻撃者が対象のTeamCityサーバへHTTP(S)アクセス可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証チェックを回避され、限定的な管理者アクションを実行される ・TeamCityサーバの管理権限を取得される ・機密情報の取得、設定情報の改変、サービス影響につながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み (NVD) ・ITW:確認済み。トレンドマイクロは、CVE-2024-27198およびCVE-2024-27199を悪用しようとする攻撃者活動を確認したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-27199 https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces that CISA has added eight known‑exploited vulnerabilities to its catalog, detailing active exploitation evidence, technical impact, and available vendor patches for each CVE.

    000415.9K
    43.6K followersView on X
  • VulnCheck@VulnCheckAI
    Active Exploitation

    Cisco disclosed six new Catalyst SD-WAN Manager vulnerabilities in the past few weeks, half already exploited in the wild. While attention has focused on CVE-2026-20127, VulnCheck assesses CVE-2026-20133 may pose greater risk than some realize. Report: https://www.vulncheck.com/blog/cisco-sd-wan-manager-vulns

    Post summary

    Cisco reported six Catalyst SD‑WAN Manager vulnerabilities, with several already seen used in real‑world attacks, highlighting CVE‑2026‑20127 and CVE‑2026‑20133.

    00040171
    662 followersView on X
  • Autumn Good@autumn_good_35
    General

    『The VulnCheck research team assesses that CVE-2026-20133 is a higher risk than defenders may realize, and is likely to be exploited — if exploitation isn’t already ongoing under the radar.』 Herding Cats: Recent Cisco SD-WAN Manager Vulnerabilities https://www.vulncheck.com/blog/cisco-sd-wan-manager-vulns

    Post summary

    The post highlights that CVE‑2026‑20133 may pose a higher risk and could be exploited, but offers no evidence, PoC, or technical details.

    00021384
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/04/20:Cisco Catalyst SD-WAN Manager の脆弱性 CVE-2026-20122/20128/20133 を登録 https://iototsecnews.jp/2026/04/21/cisa-alerts-defenders-to-exploited-cisco-catalyst-sd-wan-manager-security-flaws/ 今回の Cisco Catalyst SD-WAN Manager に関する警告は、主に三つの脆弱性が原因となっています。機密情報が露出してしまう CVE-2026-20133 、不適切なファイル処理により特権 API が悪用される CVE-2026-20122 、そしてパスワードが復元可能な形式で保存されていた CVE-2026-20128 です。これらが組み合わさることで、遠隔の攻撃者に管理権限を奪われ、システムの設定を自由に書き換えられるリスクが生じています。特に、本来守られるべき認証情報の管理不備や API の処理の甘さが、攻撃者にとっての大きな突破口となっています。ご利用のチームは、ご注意ください。 #CatalystSDWANManager #CISA #Cisco #CVE202620122 #CVE202620128 #CVE202620133 #Exploit #KEV #Vulnerability

    Post summary

    CISA alerts that three Cisco Catalyst SD‑WAN Manager CVEs are actively exploited, enabling remote attackers to gain admin rights and alter system settings, and urges teams to take precautions.

    01001167
    486 followersView on X
  • Dennis@DennisF
    Active Exploitation

    Cisco CVE-2026-20133 Targeted in Active Attacks https://decipher.sc/2026/04/22/cisco-cve-2026-20133-targeted-in-active-attacks/ #decipher #deciphersec

    Post summary

    The post announces that Cisco CVE-2026-20133 is currently being targeted in active attacks, indicating real‑world exploitation.

    01010156
    5.6K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-20133 in Cisco SD-WAN Manager to access sensitive information, then escalating privileges and moving laterally across networks. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/cisa-flags-new-sd-wan-flaw-as-actively-exploited-in-attacks-cve-2026-20133

    Post summary

    TRC analysis confirms that CVE‑2026‑20133 is actively exploited against Cisco SD‑WAN Manager, with attackers accessing data, escalating privileges, and moving laterally, as detailed in the referenced breakdown.

    10010104
    1.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-20133 is rooted in insufficient file system access restrictions in the SD-WAN Manager's web-facing API layer. An unauthenticated remote attacker can craft HTTP requests that traverse outside the intended document root or API boundary and read arbitrary files from…

    Post summary

    CVE-2026-20133 is an insufficient file‑system access issue in SD‑WAN Manager’s web API that permits unauthenticated remote file reads via URL traversal.

    1000043
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager (formerly vManage) < 20.18 CISA KEV: Yes — federal deadline passed April 24 (CVE-2026-20133), May 8 (CVE-2026-20128) Exploitation Status: Actively exploited in…

    Post summary

    The CVEs CVE-2026-20133, CVE-2026-20128, CVE-2026-20122, and CVE-2026-20127 affect Cisco Catalyst SD-WAN Manager (vManage) versions prior to 20.18, with CISA KEV deadlines passed and reports of active exploitation in the wild.

    1000075
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-20133: CVEs: CVE-2026-20133 · CVE-2026-20128 · CVE-2026-20122 · CVE-2026-20127 Product: Cisco Catalyst SD-WAN Manager formerly vManage < 20.18 CISA KEV: Yes — federal deadline passed April 24 CVE-2026-20133, May 8 CVE-2026-20128 Exploitation Status: Actively…

    Post summary

    The excerpt reports that CVE‑2026‑20133 is on the CISA KEV list with a federal deadline that has passed and notes active exploitation, but provides no PoC, exploit code, patch, or detailed technical information.

    1000078
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR CISA has added CVE-2026-20133 (CVSS 7.5) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. The flaw allows unauthenticated attackers to read sensitive information from Catalyst SD-WAN Manager (Cisco's central network control…

    Post summary

    CISA has confirmed that CVE-2026-20133 is being actively exploited, allowing unauthenticated attackers to read sensitive data from Cisco Catalyst SD‑WAN Manager. No patch or PoC information is provided in the announcement.

    1000052
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Catalyst SD-WAN Manager Zero-Auth Information Disclosure: CISA Flags CVE-2026-20133 as Actively Exploited. CISA Flags Catalyst SD-WAN Manager Vulnerability as Actively Exploited—Federal Agencies Now in Enforcement Window

    Post summary

    CISA has declared CVE-2026-20133, a zero‑auth information disclosure in Catalyst SD‑WAN Manager, as actively exploited, triggering an enforcement window for federal agencies.

    1000049
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Vulnerability: CVE-2026-20133 (Information Disclosure) CVSS Score: 7.5 (High) Attack Vector: Network, Unauthenticated Affected Product: Cisco Catalyst SD-WAN Manager (vManage) Patch Status: Available (February 2026)

    Post summary

    CVE‑2026‑20133 is an information‑disclosure flaw in Cisco Catalyst SD‑WAN Manager with a CVSS score of 7.5, for which a patch was released in February 2026.

    10000111
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-20133: CISA added CVE-2026-20133 to KEV for Cisco Catalyst SD-WAN Manager; active exploitation enables remote viewing of sensitive information.

    Post summary

    CISA listed CVE-2026-20133 on KEV, confirming it is actively exploited to remotely view sensitive data in Cisco Catalyst SD‑WAN Manager.

    1000057
    151 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.6--

Explore more