CVE-2026-20312 is a high-severity information disclosure vulnerability affecting Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. It represents multiple internally discovered cleartext storage of sensitive information issues addressed through Cisco Catalyst SD-WAN security hardening releases. The weakness is classified as CWE-312. The available information indicates that sensitive data, including credentials or other secrets, may be stored in cleartext within affected SD-WAN software, creating exposure if an attacker can access the affected system or its stored data. Cisco describes the issue as remotely exploitable and assigns CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with a base score of 8.8.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity Catalyst SD-WAN vulnerability involving cleartext storage of sensitive information.
A high-severity Cisco Catalyst SD-WAN Software vulnerability involving cleartext storage of sensitive information, potentially exposing credentials or secrets.
A cleartext storage of sensitive information vulnerability in Cisco Catalyst SD-WAN Software.
An information disclosure vulnerability grouping in Cisco Catalyst SD-WAN hardening releases involving cleartext storage of sensitive information.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.