HomeSecurityCVE-2026-20262: Cisco SD-WAN Manager under active exploitation

CVE-2026-20262: Cisco SD-WAN Manager actively exploited

Cisco has released urgent security updates for a critical vulnerability in Cisco Catalyst SD-WAN Manager that is already being actively exploited online. The vulnerability, codenamed CVE-2026-20262 , allows a authenticated remote attacker to create or replace arbitrary files in the affected device’s file system — a capability that could lead to a complete root- level compromise . The fact that the exploit was already in place before widespread public disclosure makes this essentially a zero-day scenario.

See also: Cisco: Two vulnerabilities in Catalyst SD-WAN Manager actively exploited

CVE-2026-20262 - SecNews.gr

CVE -2026-20262 is located in the web UI of Cisco Catalyst SD-WAN Manager (formerly known as SD-WAN vManage) and results from insufficient validation of data provided by the user during the file upload process. An attacker can exploit this behavior by sending specially crafted HTTP requests to an affected API endpoint. Successful exploitation requires valid credentials with at least write permissions — even a low-privilege account may suffice, according to available evidence.

Cisco assigned the vulnerability a CVSS score of 6.5/10.0 , classifying it as moderate severity. However, security analysts point out that this rating underestimates the true risk: Catalyst SD-WAN Manager is a central infrastructure management system, and a successful compromise of it could impact an organization's entire SD-WAN network. Arbitrary file write bugs like this one are often used as a stepping stone to root- level privilege escalation .

CVE-2026-20262: Technical details and affected products

The vulnerability CVE-2026-20262 affects all types of Cisco Catalyst SD-WAN Manager, regardless of environment. Specifically, the following are affected: Cisco Catalyst SD-WAN Manager On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed) , and Cisco SD-WAN for Government (FedRAMP). This means that both government organizations and companies using cloud-managed solutions are at risk.

The patched versions released by Cisco are: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2. Organizations using versions 20.9.9.1 or earlier, 20.12.7.1 or earlier, 20.15.4.4 or earlier, 20.15.5.2 or earlier, 20.18.3.0 or earlier, and 26.1.1.1 or earlier should immediately upgrade to the corresponding patched versions.

See also: Cisco Catalyst SD-WAN Manager: Vulnerability exploited in attacks

CVE-2026-20262 Cisco Catalyst SD-WAN Manager vulnerability active exploitation

Cisco has shared Indicators of Compromise (IoC ) related to the malicious activity. Organizations are encouraged to check the /var/log/nms/vmanage-server.log log file for suspicious WAR file uploads . A typical example of malicious activity that has been identified involves deploying a file named suspicious.war and then interacting with it via HTTP POST requests to JSP files.

It is worth noting that CVE-2026-20262 is the eighth vulnerability affecting Cisco SD-WAN that has been identified as actively exploited this year. The exploitation of some of these vulnerabilities has been attributed to an APT group known as UAT-8616, indicating that state-owned or state-backed threat actors are actively targeting SD-WAN. Earlier in 2026, Cisco also addressed CVE-2026-20182, a critical authentication bypassinCatalyst SD-WAN Controllers, which was also exploited before the patch was released.

The US Cybersecurity and Infrastructure Security Agency ( CISA ) added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) list on June 15, 2026 , confirming its active exploitation. Federal agencies ( FCEB ) are required to implement the fixes by June 29, 2026. Inclusion in KEV is an important external validation: once a vulnerability is listed there, it is treated as a confirmed active threat that requires immediate remediation.

See also: Cisco plans to acquire Astrix Security

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 2

To protect their systems, organizations should apply available updates immediately, prioritizing versions that are accessible from the web. Additionally, it is recommended to audit and restrict access credentials to the SD-WAN Manager, inspect logs for suspicious file upload activity, and segment access at the management level. If signs of a breach are found, analysts recommend assuming the system has already been compromised and initiating a full investigation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS