Cisco released fixes for a zero-day in Catalyst SD-WAN Manager that attackers were already using to gain deeper control of vulnerable systems. The flaw, CVE-2026-20262, affects SD-WAN vManage deployments including on-prem, Cloud, Cloud-Pro, and FedRAMP environments. Cisco says an authenticated remote attacker can abuse insufficient input validation in a file-upload API to create or overwrite files, then escalate privileges to root. Fixed releases include 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2.
Why it matters: Organizations using Cisco SD-WAN management systems should treat this as urgent because it was exploited before patches were available and can lead to full system compromise. Update immediately and review Cisco's indicators of compromise, especially file-upload attempts involving index.jsp and .war files in vmanage logs.
Eduard Kovacs
2026.06.16
98% relevant
This article is a direct report on the same event, adding that Cisco described the bug as an arbitrary file write in an affected API endpoint, said exploitation was seen in limited attacks in June 2026, and noted CISA's June 29 federal remediation deadline.
2026.06.15
98% relevant
This article reports the same underlying event: Cisco's patch for actively exploited Catalyst SD-WAN Manager flaw CVE-2026-20262, including that exploitation was observed in June 2026, the bug affects the web UI file-upload path, requires valid low-privilege credentials, and was added to CISA's KEV catalog with a federal patch deadline.
Sergiu Gatlan
2026.06.15
100% relevant
This article establishes a distinct newly patched Cisco SD-WAN zero-day event centered on CVE-2026-20262, which is separate from the already tracked unpatched Catalyst SD-WAN Manager zero-day CVE-2026-20245.
← Back to all stories