ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27351
Authentication Bypass in PaperCut NG/MF Print Management Software

CVE-2023-27351 is an improper authentication flaw (CWE-287) in the SecurityRequestFilter class of PaperCut NG and MF print management software, where the authentication algorithm is improperly implemented. A remote, unauthenticated attacker can trigger it over the network with no user interaction or special privileges to bypass authentication on the affected server (CVSS 3.1: 7.5). Once authentication is bypassed, the attacker gains access to the PaperCut system; in observed campaigns this access was leveraged to deliver Cl0p and LockBit ransomware, as confirmed by Microsoft. Organizations running PaperCut NG (version 22.0.5, Build 63914, is cited in the advisory) or PaperCut MF are affected. The flaw was exploited as a zero-day, is CISA KEV-listed (added 2026-04-20) with known ransomware use, and EPSS places the 30-day exploitation probability at 78.1%.

Do: Upgrade PaperCut NG/MF to the fixed release per the vendor's emergency patch advisory, first confirming the running build (NG 22.0.5, Build 63914, is cited as affected). Restrict internet-facing access to PaperCut servers and hunt for signs of post-exploitation, given confirmed use to deliver Cl0p and LockBit ransomware. US federal agencies must apply mitigations per CISA BOD 22-01 (or vendor instructions) or discontinue use of the product if mitigations are unavailable.

7.578% KEV ransomware
  • PaperCut NG 22.0.5 (Build 63914) explicitly cited as affected; CISA lists PaperCut NG broadly without a full version range
  • PaperCut MF affected per CISA listing; no specific version range provided in the data
large≈75,000+ sites/organizations (PaperCut NG/MF is deployed at tens of thousands of organizations; public scans have found thousands of servers directly…
CVE-2024-27199
Path Traversal in JetBrains TeamCity Allows Limited Admin Actions

JetBrains TeamCity, a widely used continuous integration/continuous delivery (CI/CD) server, contains a relative path traversal vulnerability (CWE-23) in which the application fails to properly neutralize traversal sequences in file paths. An attacker who can reach the vulnerable component can supply crafted relative paths that escape the intended directory, gaining the ability to perform limited administrative actions on the TeamCity server. Any organization running an affected JetBrains TeamCity deployment, especially instances exposed to the internet or reachable by untrusted users, is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20 with known ransomware use, and the EPSS model assigns it a 100% probability of exploitation within the next 30 days. No public proof-of-concept is known, but the KEV listing confirms active exploitation in the wild per CISA.

Do: Upgrade TeamCity to the patched release identified in JetBrains' security bulletin, or if patching is not immediately possible, apply vendor-recommended mitigations and restrict internet access to the server; federal agencies must follow BOD 22-01 guidance, including for cloud service offerings, or discontinue use if mitigations are unavailable. Given the known ransomware association, review TeamCity logs, admin accounts, and build-agent activity for signs of tampering as part of remediation.

7.3100% KEV ransomware PoC
  • JetBrains TeamCity Affected as listed by CISA; the source data provides no specific affected version ranges, so verify exact affected and patched versions in JetBrains' security b
large~10,000-30,000 TeamCity server deployments, with a meaningful share of those exposed directly to the internet (order of magnitude 10^4)
CVE-2025-2749
Path Traversal to Authenticated RCE in Kentico Xperience Through 13.0.178

CVE-2025-2749 is a path traversal and unrestricted file upload flaw (CWE-22/CWE-434) in the Staging Sync Server component of Kentico Xperience, exploitable by an authenticated user with staging sync privileges. The user can upload arbitrary data to path-relative locations, escaping the intended upload directory and writing attacker-controlled files — including executable server-side content such as script files — anywhere the application can reach, resulting in remote code execution on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 3.1: 7.2 High, network-accessible with high privileges required). All Kentico Xperience versions through 13.0.178 are affected, primarily deployments where the Staging Sync Server endpoint is reachable by attackers or by accounts with weak or stolen credentials. The flaw is confirmed actively exploited — it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-20 — and a public technical write-up with proof-of-concept details is available from watchTowr Labs.

Do: Upgrade Kentico Xperience to a hotfix release later than 13.0.178 per the vendor's instructions (federal agencies must follow BOD 22-01 guidance or the KEV-required action by the stated deadline). Until patched, restrict access to the Staging Sync Server endpoint (e.g., via VPN/firewall allowlisting) and review high-privilege staging/sync accounts for suspicious use. Hunt for signs of compromise such as unexpected executable or script files uploaded outside intended directories and webshells in the web root, since the vulnerability is listed in CISA's KEV as actively exploited.

7.24% KEV PoC
  • Kentico Xperience all versions through 13.0.178 (inclusive)
large≈ tens of thousands (10k–100k) of Kentico Xperience deployments, with an unknown but smaller subset exposing the staging sync endpoint to the internet
CVE-2025-32975
Authentication Bypass in Quest KACE Systems Management Appliance (SSO)

Quest KACE Systems Management Appliance (SMA) versions in the 13.0.x through 14.1.x branches, prior to the fixed builds, contain an improper authentication flaw (CWE-287) in the SSO authentication handling mechanism. Because the bypass requires no valid credentials, privileges, or user interaction and is reachable over the network, an attacker who can reach the appliance can impersonate legitimate users and achieve complete administrative takeover. Any organization running an affected SMA build is exposed, particularly where the appliance's web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, and press reporting describes attackers hijacking unpatched SMA systems, with compromises at roughly 60 organizations cited; ransomware use is not yet confirmed.

Do: Upgrade affected SMA deployments to the fixed build for their branch — 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4) or later — prioritizing internet-facing appliances. Since the flaw is actively exploited and grants full admin takeover, review appliance logs and administrator accounts for signs of compromise (unexpected SSO sessions, new or altered accounts) and restrict access to the SMA web interface to trusted networks per Quest's guidance. U.S. federal agencies must apply the required mitigations or discontinue use under BOD 22-01 by the KEV deadline.

10.02% KEV
  • Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385
  • Quest KACE Systems Management Appliance (SMA) 13.1.x before 13.1.81
  • Quest KACE Systems Management Appliance (SMA) 13.2.x before 13.2.183
  • +2 more
largetens of thousands of deployed SMA appliances worldwide, with likely only a low-thousands subset internet-exposed
CVE-2025-48700
Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, and 10.1 contain a cross-site scripting (XSS) flaw in the Classic UI caused by insufficient sanitization of HTML email content, involving crafted tag structures and attribute values that use @import directives and other script injection vectors. An attacker triggers it simply by getting a user to view a crafted email message in the Classic UI, with no additional user interaction required. Successful exploitation executes arbitrary JavaScript within the victim's session, potentially exposing sensitive mailbox information or enabling unauthorized actions under the victim's identity. Any organization running the affected ZCS branches — particularly internet-facing mail servers whose users receive untrusted email — is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, confirming active exploitation in the wild; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at about 1.7%.

Do: Upgrade ZCS to the latest patched builds of the affected 8.8.15/9.0/10.0/10.1 branches per Synacor/Zimbra's security advisory (no specific fixed version is listed here); federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Because the flaw is specific to the Classic UI, having users work in the Modern UI instead of the Classic UI reduces exposure until patching is complete. Review mail server and web client logs for users who viewed suspicious HTML-formatted messages as an indicator of targeting.

6.12% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) Classic UI 8.8.15, 9.0, 10.0, and 10.1
largeon the order of tens of thousands of internet-exposed Zimbra servers
CVE-2026-20122
Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown.

Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable.

5.425% KEV
  • Cisco Catalyst SD-WAN Manager
large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide
CVE-2026-20133
+1 in the same advisory: …20128
Actively Exploited Information Disclosure in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager, the central management and monitoring platform for Cisco SD-WAN fabrics (formerly known as vManage), contains a sensitive-information-exposure flaw (CWE-200) that allows remote attackers to view sensitive information on affected systems. The available data does not specify the exact trigger path or authentication requirements, but the flaw is remotely exploitable by unauthorized actors. An attacker gains access to sensitive information held on the management platform, which aggregates inventory, configuration, and telemetry for an entire SD-WAN overlay, potentially aiding follow-on attacks. Any organization running an affected release of Cisco Catalyst SD-WAN Manager is in scope. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-04-20, confirming exploitation in the wild, and EPSS assigns a 31.4% probability of exploitation within 30 days (98th percentile), although CVSS scoring is pending and no public proof-of-concept is known.

Do: Inventory your environment for internet-exposed Catalyst SD-WAN Manager instances and review access logs for signs of unauthorized retrieval of sensitive information, since the flaw is listed as exploited in the wild. Apply the vendor fix referenced in Cisco's advisory for CVE-2026-20133 when available, and follow CISA's Emergency Directive 26-03 and the CISA 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'; federal agencies must adhere to applicable BOD 22-01 mitigation timelines or discontinue use of the product if mitigations are unavailable.

7.531% KEV
  • Cisco Catalyst SD-WAN Manager
large≈tens of thousands of deployments (Cisco has publicly cited 30,000+ SD-WAN customers, each operating at least one Manager controller)
Full article268 words · extracted from helpnetsecurity.com · click to collapse

CISA added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a Cisco Catalyst SD-WAN Manager vulnerability (CVE-2026-20133) that Cisco has yet to flag as exploited.

Three Cisco Catalyst SD-WAN Manager vulnerabilities

Alongside CVE-2026-20133, CISA has also listed CVE-2026-20128 and CVE-2026-20122 – two other Catalyst SD-WAN Manager vulnerabilities – as being leveraged in attacks.

The latter two flaws have been confirmed as actively exploited by Cisco in early March 2026.

In March, VulnCheck’s research team assessed that “CVE-2026-20133 is a higher risk than defenders may realize, and is likely to be exploited — if exploitation isn’t already ongoing under the radar.”

It’s currently unclear whether CVE-2026-20133 was exploited alongside CVE-2026-20128 and CVE-2026-20122 in those initial attacks.

The remaining five security holes

This latest batch of additions to CISA’s Known Exploited Vulnerabilities catalog include:

  • CVE-2023-27351, a PaperCut NG/MF vulnerability that has been exploited since early 2023 by Lace Tempest, a Clop ransomware affiliate
  • CVE-2024-27199, a JetBrains TeamCity flaw leveraged by attackers since early 2024
  • CVE-2025-2749, a Kentico Xperience bug with no public reports of exploitation
  • CVE-2025-32975, a vulnerability affecting Quest KACE Systems Management Appliances. In March 2026, Arctic Wolf observed “malicious activity in customer environments potentially linked to [its] exploitation.”
  • CVE-2025-48700, a zero-click cross-site scripting vulnerability in Synacor’s Zimbra Collaboration Suite that, according to the State Special Communications Service of Ukraine, has been exploited since late September 2025.

CISA has ordered US federal civilian agencies to address all 8 flaws by April 20, 2026.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/21/cisa-flags-another-cisco-catalyst-sd-wan-manager-bug-as-exploited-cve-2026-20133/