Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Khaled Alshaikh

#32375of 56,335
8.6Total CVSS
Vulnerabilities · 1
PT-2026-40962
8.6
2026-05-14
Cisco · Catalyst Sd-Wan Manager · CVE-2026-20224
**Name of the Vulnerable Software and Affected Versions** Cisco Catalyst SD-WAN Manager (affected versions not specified) **Description** A flaw in the web UI of Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage, allows an unauthenticated remote attacker to read arbitrary files from the affected system. This issue results from the improper handling of XML External Entity (XXE) entries—a type of attack where an XML parser processes external entities within an XML document—during the parsing of an XML file. An attacker can trigger this by sending a specially crafted request. Real-world exploit activity has been observed using six XXE variants to read local filesystem paths. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.