• News/
  • https://www.bleepingcomputer.com/news/security/cisa-flags-new-sd-wan-flaw-as-actively-exploited-in-attacks/

CISA flags new SD-WAN flaw as actively exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 21, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks. Catalyst SD-WAN Manager (formerly known as vManage) is a network management software that helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard. Cisco patched this information disclosure vulnerability (CVE-2026-20133) in late February, saying that it allows unauthenticated remote attackers to access sensitive information on unpatched devices. "This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system," Cisco said at the time. "A successful exploit could allow the attacker to read sensitive information on the underlying operating system." One week later, the company revealed that two other security flaws it had patched the same day (CVE-2026-20128 and CVE-2026-20122)were being exploited in the wild. On Monday, CISA added CVE-2026-20133 to its Known Exploited Vulnerabilities (KEV) Catalog, "based on evidence of active exploitation," and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their networks until Friday, April 24. "Please adhere to CISA's guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA's Emergency Directive 26-03 and CISA's Hunt...

Read full article

Affected Software

2 affected components
Cisco Catalyst SD-WAN Manager (formerly vManage)
Cisco Secure Firewall Management Center (FMC)

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly identified vulnerability in the Cisco Catalyst SD-WAN Manager that is actively being exploited in cyber attacks.

2

What security implications are discussed in the article?

The article highlights the urgent need for government agencies to secure their systems against this vulnerability within four days as it is currently being exploited by attackers.

3

What products or software are affected by this vulnerability?

The Cisco Catalyst SD-WAN Manager and the Cisco Secure Firewall Management Center are the products affected by this vulnerability.

4

Who has issued warnings regarding this vulnerability?

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about the vulnerability.

5

What actions are recommended for organizations in response to this vulnerability?

Organizations are urged to patch and secure their systems against the identified vulnerability immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203