Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Khaled Alshaikh

#30663of 53,632
8.6Total CVSS
Vulnerabilities · 1
PT-2026-40962
8.6
2026-05-14
Cisco · Catalyst Sd-Wan Manager · CVE-2026-20224
**Name of the Vulnerable Software and Affected Versions** Cisco Catalyst SD-WAN Manager (affected versions not specified) **Description** A flaw in the web UI of Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage, allows an unauthenticated remote attacker to read arbitrary files from the affected system. This issue results from the improper handling of XML External Entity (XXE) entries—a type of attack where an XML parser processes external entities within an XML document—during the parsing of an XML file. An attacker can trigger this by sending a specially crafted request. Real-world exploit activity has been observed using six XXE variants to read local filesystem paths. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.