VYPR

Catalyst SD-WAN Manager

by Cisco Systems, Inc.

CVEs (42)

  • CVE-2026-20182CriKEVMay 14, 2026
    risk 0.86cvss 10.0epss 0.88

    May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this…

  • CVE-2026-20127CriKEVFeb 25, 2026
    risk 0.84cvss 10.0epss 0.58

    A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to…

  • CVE-2026-20128HigKEVFeb 25, 2026
    risk 0.61cvss 7.5epss 0.05

    A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an…

  • CVE-2026-20224HigMay 14, 2026
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This…

  • CVE-2026-20262MedKEVJun 15, 2026
    risk 0.54cvss 6.5epss 0.08

    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does…

  • CVE-2026-20133MedKEVFeb 25, 2026
    risk 0.54cvss 6.5epss 0.10

    A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could…

  • CVE-2026-20122MedKEVFeb 25, 2026
    risk 0.47cvss 5.4epss 0.07

    A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected…

  • CVE-2026-20210MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because…

  • CVE-2026-20209MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability…

  • CVE-2022-20775KEVSep 30, 2022
    risk 0.12cvss epss 0.12

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running…

  • CVE-2020-26073Nov 18, 2024
    risk 0.07cvss epss 0.12

    A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within…

  • CVE-2026-20108Mar 25, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient…

  • CVE-2026-20129Feb 25, 2026
    risk 0.00cvss epss 0.01

    A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that…

  • CVE-2026-20126Feb 25, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An…

  • CVE-2025-20349Nov 13, 2025
    risk 0.00cvss epss 0.00

    A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user. This vulnerability is due to insufficient validation of user-supplied input in REST API request…

  • CVE-2025-20155May 7, 2025
    risk 0.00cvss epss 0.00

    A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software…

  • CVE-2025-20147May 7, 2025
    risk 0.00cvss epss 0.00

    A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. This vulnerability is due to…

  • CVE-2025-20216May 7, 2025
    risk 0.00cvss epss 0.00

    A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the…

  • CVE-2025-20187May 7, 2025
    risk 0.00cvss epss 0.01

    A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to…

  • CVE-2025-20122May 7, 2025
    risk 0.00cvss epss 0.00

    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An…

Page 1 of 3