CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Cisco Patches Actively Exploited SD-WAN Manager Vulnerability CVE-2026-20262

June 25, 2026

Cisco has released security updates to address a medium-severity vulnerability in its Catalyst SD-WAN Manager (formerly SD-WAN vManage) that is being actively exploited in the wild. The flaw, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.

According to Cisco’s advisory, the vulnerability exists in the web UI of the Catalyst SD-WAN Manager and could allow an authenticated, remote attacker to create or overwrite any file on the filesystem of an affected system. The issue stems from inadequate validation of user-supplied input during a file upload process. An attacker could exploit this behavior by sending crafted HTTP requests to an affected API endpoint, potentially leading to privilege escalation to root. However, successful exploitation requires the attacker to have valid credentials with at least write access.

The vulnerability impacts multiple Cisco products regardless of deployment type, including Cisco Catalyst SD-WAN Manager On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). Cisco has released patches for affected versions, with fixes available in releases such as 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2.

Cisco stated that it became aware of limited exploitation of this vulnerability in June 2026, which was discovered during internal security testing. The company has shared indicators of compromise, urging customers to audit log files for suspicious WAR file uploads and other signs of malicious activity. CVE-2026-20262 is the eighth actively exploited Cisco SD-WAN flaw this year, with some previous exploits attributed to the advanced persistent threat actor UAT-8616. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by June 29, 2026.

CVEs: CVE-2026-20262, CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, CVE-2022-20775, CVE-2026-11645

Attack groups: UAT-8616

Companies: Cisco, CISA

Products: Cisco Catalyst SD-WAN Manager, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), Cisco SD-WAN for Government (FedRAMP)