CVE-2026-20224

HIGH

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected syste...

Affects 0 products across 5 vendors.

BCS5.86
CVSS 3.18.6
EPSS1.0%
Percentile60th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an unauthenticated remote attacker to read arbitrary files due to improper handling of XML External Entity (XXE) entries.

BSID: BS-2026-GLOBAL-271237-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20224?
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an unauthenticated remote attacker to read arbitrary files due to improper handling of XML External Entity (XXE) entries.
What is the CVSS score for CVE-2026-20224?
CVE-2026-20224 has CVSS 8.6 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. EPSS: 1.0%.
Is CVE-2026-20224 actively exploited?
No confirmed active exploitation of CVE-2026-20224 as of 2026-06-30.
How do I remediate CVE-2026-20224?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R PSIRT: [email protected]
What systems are affected by CVE-2026-20224?
CVE-2026-20224 affects: Catalyst, Cisco, Files, Francisco Burzi, Valid.
Vulnerability Details
CVE IDCVE-2026-20224
BSIDBS-2026-GLOBAL-271237-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Published2026-05-14
Last Modified2026-06-29
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves an unauthenticated remote attacker sending a specially crafted XML file to the web UI of the Cisco Catalyst SD-WAN Manager, which improperly handles XML External Entity (XXE) entries, leading to the disclosure of arbitrary files.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Catalyst —
Cisco —
Files —
Francisco Burzi —
Valid —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashcf1a4ffa111d09d2d5371a75fea251c1ec29509f8fa22ae2c7fede549e3d0fa50019f2105e1956362eda3c646491d8c966ac3f8346276ec7f45148f47e558e4d
Related CVEs affecting Catalyst
CVE-2026-26009 9.9 Catalyst is a platform built for enterprise game server hosts, game communiti... CVE-2025-20341 8.8 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an aut... CVE-2026-20084 8.6 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could a... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc... CVE-2025-40920 8.6 Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Per...
View all Catalyst CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →