Cisco patches exploited Catalyst SD-WAN Manager zero-day CVE-2026-20262 that can lead to root access

Cisco released fixes for a zero-day in Catalyst SD-WAN Manager that attackers were already using to gain deeper control of vulnerable systems. The flaw, CVE-2026-20262, affects SD-WAN vManage deployments including on-prem, Cloud, Cloud-Pro, and FedRAMP environments. Cisco says an authenticated remote attacker can abuse insufficient input validation in a file-upload API to create or overwrite files, then escalate privileges to root. Fixed releases include 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2.
Why it matters: Organizations using Cisco SD-WAN management systems should treat this as urgent because it was exploited before patches were available and can lead to full system compromise. Update immediately and review Cisco's indicators of compromise, especially file-upload attempts involving index.jsp and .war files in vmanage logs.

Sources

Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks
Eduard Kovacs 2026.06.16 98% relevant
This article is a direct report on the same event, adding that Cisco described the bug as an arbitrary file write in an affected API endpoint, said exploitation was seen in limited attacks in June 2026, and noted CISA's June 29 federal remediation deadline.
Cisco SD-WAN make-me-root bug under attack
2026.06.15 98% relevant
This article reports the same underlying event: Cisco's patch for actively exploited Catalyst SD-WAN Manager flaw CVE-2026-20262, including that exploitation was observed in June 2026, the bug affects the web UI file-upload path, requires valid low-privilege credentials, and was added to CISA's KEV catalog with a federal patch deadline.
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Sergiu Gatlan 2026.06.15 100% relevant
This article establishes a distinct newly patched Cisco SD-WAN zero-day event centered on CVE-2026-20262, which is separate from the already tracked unpatched Catalyst SD-WAN Manager zero-day CVE-2026-20245.
← Back to all stories