🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure (CVE-2026-20133) | MSSP Advisory
High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-20133
CVSS Score6.5
Affectedcatalyst_sd-wan_manager
📋Executive Summary
CISA flagged CVE-2026-20133 affecting Cisco Catalyst SD-WAN Manager for exposing sensitive information to remote attackers. The vulnerability allows unauthorized actors to view sensitive data on affected systems, and CISA has issued Emergency Directive 26-03 specifically for Cisco SD-WAN devices.
⚠️Why It Matters for MSSPs
Your SD-WAN infrastructure could expose sensitive client data and network credentials to remote attackers. Client environments using Cisco SD-WAN Manager face immediate information disclosure risks, and you need to advise them on exposure assessment and mitigation within days.
✅Recommended Action
Inventory all client environments with Cisco Catalyst SD-WAN Manager immediately and assess exposure using CISA's Emergency Directive 26-03 guidance. Contact affected clients within 24 hours to discuss the vulnerability and coordinate patching or mitigation steps. Document your advisory efforts and client responses for compliance with service agreements.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.