cbcvebase.
CVE-2026-20133
published 2026-02-25

CVE-2026-20133: A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This…

PriorityP184high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-23
Exploited in the wild
EPSS
10.24%
95.1th percentile
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Affected

167 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan
ciscocatalyst_sd-wan_manager< 20.9.8.220.9.8.2
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.10 < 20.12.5.320.12.5.3
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.220.15.4.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.18.2.120.18.2.1
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager

Detection & IOCsextracted from sources · hover to see the quote

ip38.181.52[.]89
ip89.125.244[.]33
ip89.125.244[.]51
ip38.60.214[.]92
ip65.20.67[.]134
ip104.233.156[.]1
ip194.233.100[.]40
port7443
port31337
otherfece5b954e69b2c6a8d0a1029631a0d7
path/api/v1/handshake
path/api/v1/results
path/api/v1/payloads
path/api/v1/exfiltrate
path/api/v1/tasks
path/api/v1/init
  • Detect Cluster 2 Behinder webshell variant by its use of Base64-only encoding (no AES encryption), distinguishing it from standard Behinder variants
  • Detect Cluster 10 post-exploitation credential theft targeting admin hashdumps, JWT key chunks used for REST API authentication, and AWS credentials for vManage
  • Detect Mythic C2 infrastructure on 194[.]163[.]175[.]135 by TLS certificate serial number fece5b954e69b2c6a8d0a1029631a0d7 on port 7443
  • IP 83.229.126[.]195 is both an XMRig download source (Cluster 7) and a known Cobalt Strike C2 server — block and alert on connections to this IP
  • ·CVE-2026-20133 exploitation is chained with CVE-2026-20128 and CVE-2026-20122; exploitation of CVE-2026-20133 alone may not yield full device access — detection should account for the three-CVE chain
  • ·Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by CVE-2026-20133
  • ·Active exploitation of CVE-2026-20133 (chained with CVE-2026-20128 and CVE-2026-20122) began in March 2026 following public release of ZeroZenX Labs PoC code; unpatched systems remain at high risk

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.