LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-20224

cisco · catalyst sd-wan manager

Published
CVSS8.6
Severityhigh
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-20224

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-20224.