CVE-2026-20224Disclosure(cisco / catalyst_sd-wan_manager)

MEDIUMCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 6d ago at 2 mentions (2026-05-14); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-05-14: 2Mentions · 2026-05-15: 2Mentions · 2026-05-17: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-05-25: 1Mentions · 2026-07-02: 1PoC Mentioned / Linked · 2026-05-17: 1Active Exploitation · 2026-05-15: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-15: 2Technical Details · 2026-05-17: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 1Technical Details · 2026-07-02: 105-1405-1505-1705-1905-2105-2507-02
Signal classification4 categories
Disclosure
666.7%
Active Exploitation
111.1%
Patch
111.1%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-142
Disclosure2
2026-05-152
Active Exploitation1Patch1
2026-05-171
Disclosure1
2026-05-191
Disclosure1
2026-05-211
Disclosure1
2026-05-251
General1
2026-07-021
Disclosure1
Full discourse9 posts
  • Defused@DefusedCyber
    Active Exploitation

    🚨 The Cisco SD-WAN vManage CVE-2026-20224 released yesterday - currently stated to have no known ITW exploitation by Cisco PSIRT - is now seeing exploit activity on the Defused honeypots Attackers are using 6 XXE variants for reading local filesystem paths. Payloads align with advisory but exploit success not verified Track exploitation of this and other Cisco honeypots 👉 https://console.defusedcyber.com/intel

    Post summary

    CVE‑2026‑20224 in Cisco SD‑WAN vManage is currently being actively exploited via multiple XXE variants, leading to local filesystem access on detected honeypots. No patch or PoC detail is provided, but the active exploitation claim is clear.

    11122966.7K
    7.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cisco fixes a critical 8.6 CVSS XXE flaw (CVE-2026-20224) in Catalyst SD-WAN Manager. Unauthenticated attackers can read arbitrary files. Patch now! #Cisco #SDWAN #CyberSecurity #InfoSec #VulnerabilityAlert #CVE202620224 #Networking #vManage #PatchNow https://securityonline.info/cisco-catalyst-sd-wan-manager-vulnerability-cve-2026-20224-xxe/ https://t.co/XqJc6phUlt

    Post summary

    Cisco has released a patch for the critical XXE vulnerability (CVE‑2026‑20224) in Catalyst SD‑WAN Manager that could allow unauthenticated attackers to read arbitrary files.

    01051466
    12.5K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW 『(直訳)Cisco Catalyst SD-WAN Controller(旧称:SD-WAN vSmart)およびCisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)のピアリング認証における脆弱性により、認証されていないリモート攻撃者が認証を回避し、影響を受けるシステム上で管理者権限を取得できる可能性があります』 CVE-2026-20209/CVE-2026-20210/CVE-2026-20224 Cisco Catalyst SD-WAN Manager Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R 『(直訳)Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、リモートの攻撃者が機密情報にアクセスしたり、権限を昇格させたり、アプリケーションへの不正アクセスを実行したりする可能性があります。』

    Post summary

    Cisco has publicly disclosed CVE‑2026‑20182 and related SD‑WAN Manager CVEs that allow unauthenticated remote attackers to bypass authentication or elevate privileges. No PoC or exploit details are offered in the text.

    01010825
    11.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Cisco ❗ CVE-2026-20224 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-cisco-6/ https://t.co/K9UXXZsIYm

    Post summary

    A brief notification of CVE-2026-20224 affecting Cisco products, with a link to additional information but no further technical or exploit details.

    00010231
    6.7K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-20224 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated… CVSS 8.6 Full analysis → https://sec.kaitan.id/cves/CVE-2026-20224 #Cisco #CyberSecurity #InfoSec

    Post summary

    The tweet announces a high‑severity vulnerability (CVSS 8.6) in Cisco Catalyst SD‑WAN Manager's web UI that could allow unauthenticated access, with no PoC, exploit, or patch information given.

    00010116
    90 followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-20224: Unauthenticated XXE File Read in Cisco Catalyst SD-WAN Manager https://breachspider.com/intel/2026-07-02-cve-2026-20224-unauthenticated-xxe-file-read-in-cisco-cataly #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces a new unauthenticated XXE file-reading vulnerability (CVE‑2026‑20224) in Cisco Catalyst SD-WAN Manager, offering technical details but no PoC, exploit code, or patch information.

    0000070
    2.3K followersView on X
  • しーにゃ♪@公式@Syynya
    Disclosure

    Cisco Catalyst SD-WAN Managerの脆弱性(CVE-2026-20224)、認証不要で任意ファイル読み取りの恐れ https://rocket-boys.co.jp/security-measures-lab/cisco-sd-wan-manager-cve-2026-20224-file-read/

    Post summary

    The article announces a new CVE involving unauthenticated arbitrary file read in Cisco Catalyst SD‑WAN Manager, but lacks details on PoC, exploit code, active exploitation, or patch availability.

    0000084
    913 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Cisco Catalyst SD-WAN Managerの脆弱性(CVE-2026-20224)、認証不要で任意ファイル読み取りの恐れ https://rocket-boys.co.jp/security-measures-lab/cisco-sd-wan-manager-cve-2026-20224-file-read/ #セキュリティ対策Lab #security #securitynews

    Post summary

    A vulnerability (CVE‑2026‑20224) in Cisco Catalyst SD‑WAN Manager allows unauthenticated attackers to read arbitrary files.

    00000175
    407 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-20224 | Cisco Catalyst SD-WAN Manager up to 26.1.1_LI_Images XML File Parser xml external entity reference (cisco-sa-sdwan-mltvnps2-JxpWm7R / WID-SEC-2026-1540) https://ift.tt/4FSuQVk A vulnerability classified as problematic was found in Cisco Catalyst SD-WAN Manager…

    Post summary

    The snippet reports a new XML external entity (XXE) vulnerability in Cisco Catalyst SD-WAN Manager, links to further information, but provides no evidence of exploitation, patches, or misclassifications.

    0000075
    974 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.7--

Explore more