CVE-2026-20224
published 2026-05-14CVE-2026-20224: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary…
PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.70%
48.7th percentile
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.
This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.
Affected
371 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | < 20.9.9.1 | 20.9.9.1 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.10 < 20.12.5.4 | 20.12.5.4 |
| cisco | catalyst_sd-wan_manager | >= 20.12.6 < 20.12.6.2 | 20.12.6.2 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.4 | 20.15.4.4 |
| cisco | catalyst_sd-wan_manager | >= 20.15.5 < 20.15.5.2 | 20.15.5.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18.2.2 | 20.18.2.2 |
| cisco | catalyst_sd-wan_manager | >= 26.1 < 26.1.1.1 | 26.1.1.1 |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-558q-cqp2-mrc3: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbit
ghsa_unreviewed·2026-05-14
CVE-2026-20224 [HIGH] CWE-20 GHSA-558q-cqp2-mrc3: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbit
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.
This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.
VulDB
Cisco Catalyst SD-WAN Manager up to 26.1.1_LI_Images XML File Parser xml external entity reference (cisco-sa-sdwan-mltvnps2-JxpWm7R)
vuldb·2026-05-14·CVSS 8.6
CVE-2026-20224 [HIGH] Cisco Catalyst SD-WAN Manager up to 26.1.1_LI_Images XML File Parser xml external entity reference (cisco-sa-sdwan-mltvnps2-JxpWm7R)
A vulnerability classified as problematic was found in Cisco Catalyst SD-WAN Manager. The affected element is an unknown function of the component XML File Parser. The manipulation results in xml external entity reference.
This vulnerability is known as CVE-2026-20224. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-14
Published