logo

Cisco SD-WAN Manager XXE Flaw Grants Unauthenticated Access to Private Files

ID: 16786264-3173-53de-954d-35e4a67d65ae

STIX ID: report--16786264-3173-53de-954d-35e4a67d65ae

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

### Executive Summary Cisco disclosed multiple vulnerabilities in Catalyst SD-WAN Manager (vManage), most notably CVE-2026-20224, an unauthenticated XML External Entity (XXE) issue rated Critical (CVSS 8.6) that can enable remote attackers to read arbitrary files. Two additional Medium-severity privilege escalation bugs allow read-only users to obtain high privileges by exploiting sensitive session data in logs or unredacted device configuration data. Cisco reports no workarounds and provides fixed release versions, urging administrators to upgrade immediately; unsupported releases should migrate to a supported version.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.