Cisco discloses actively exploited SD-WAN Manager zero-day as CISA orders federal patch by June 29
The path-traversal flaw in Catalyst SD-WAN Manager lets an authenticated attacker overwrite files and escalate to root; Cisco's own team caught it being exploited before disclosure.
Cisco has disclosed CVE-2026-20262, a path-traversal vulnerability in the web interface of its Catalyst SD-WAN Manager (vManage), that its own Product Security Incident Response Team observed being exploited before public disclosure on June 16, 2026.
An attacker holding valid write credentials can send a crafted HTTP request to an affected API endpoint to create or overwrite any file on the underlying operating system, then escalate to root, Cisco said in its advisory. The flaw affects all deployment types: on-premises, Cloud-Pro, Cloud (Cisco Managed) and Government (FedRAMP). One indicator of compromise is attackers dropping a malicious .war file via vManage's WildFly Java application server.
Cisco found the bug during internal security testing and said it is unclear how attackers learned of it before disclosure. The fixed software versions match those Cisco released on June 12 for a prior SD-WAN zero-day, CVE-2026-20245.
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on June 15, 2026, requiring federal civilian agencies to remediate by June 29 — a 14-day window consistent with its binding operational directive on risk-based vulnerability management.
This is at least the seventh Catalyst SD-WAN Manager vulnerability exploited in attacks since the start of 2026, a run that points to an attacker with deep familiarity with the platform. Cisco has published fixed releases; administrators of unpatched systems remain exposed until they update.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
