ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20122
Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown.

Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable.

5.425% KEV
  • Cisco Catalyst SD-WAN Manager
large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide
CVE-2026-20127
Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator

A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile).

Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product.

10.088% KEV
  • Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
  • Cisco Catalyst SD-WAN Validator (formerly SD-WAN vBond Orchestrator)
large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise…
CVE-2026-20133
+1 in the same advisory: …20128
Actively Exploited Information Disclosure in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager, the central management and monitoring platform for Cisco SD-WAN fabrics (formerly known as vManage), contains a sensitive-information-exposure flaw (CWE-200) that allows remote attackers to view sensitive information on affected systems. The available data does not specify the exact trigger path or authentication requirements, but the flaw is remotely exploitable by unauthorized actors. An attacker gains access to sensitive information held on the management platform, which aggregates inventory, configuration, and telemetry for an entire SD-WAN overlay, potentially aiding follow-on attacks. Any organization running an affected release of Cisco Catalyst SD-WAN Manager is in scope. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-04-20, confirming exploitation in the wild, and EPSS assigns a 31.4% probability of exploitation within 30 days (98th percentile), although CVSS scoring is pending and no public proof-of-concept is known.

Do: Inventory your environment for internet-exposed Catalyst SD-WAN Manager instances and review access logs for signs of unauthorized retrieval of sensitive information, since the flaw is listed as exploited in the wild. Apply the vendor fix referenced in Cisco's advisory for CVE-2026-20133 when available, and follow CISA's Emergency Directive 26-03 and the CISA 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'; federal agencies must adhere to applicable BOD 22-01 mitigation timelines or discontinue use of the product if mitigations are unavailable.

7.531% KEV
  • Cisco Catalyst SD-WAN Manager
large≈tens of thousands of deployments (Cisco has publicly cited 30,000+ SD-WAN customers, each operating at least one Manager controller)
CVE-2026-20182
Authentication Bypass in Cisco Catalyst SD-WAN Control Components

CVE-2026-20182 is a critical authentication flaw (CWE-287) in the control-connection peering authentication of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond). Because the peering authentication mechanism does not work properly, an unauthenticated, remote attacker can send crafted requests during the control-connection handshake and log in to the controller as an internal, high-privileged, non-root user without valid credentials. With this access, the attacker can reach NETCONF and manipulate network configuration across the entire SD-WAN fabric. Any organization running these Catalyst SD-WAN control components is affected, and the flaw carries a CVSS 3.1 score of 10.0 and a 91.5% EPSS score. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-14, confirming exploitation in the wild, amid a series of exploited Cisco SD-WAN zero-days including a compromise at a communications service provider.

Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components to the fixed releases identified in Cisco's May 2026 advisory (version numbers are not provided in this data). Use the advisory's 'show control connections' guidance to inspect control-connection handshaking for anomalies and audit for unauthorized high-privileged non-root accounts and unexpected NETCONF sessions. Operators — especially federal agencies — should follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices, including restricting internet exposure of SD-WAN management interfaces until patched.

10.092% KEV
  • Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
  • Cisco Catalyst SD-WAN Validator / vBond Orchestrator (formerly SD-WAN vBond)
largeon the order of tens of thousands of affected control-plane systems (controllers, managers, validators) across enterprise, service-provider, and government…
CVE-2026-20245
Command Injection as Root in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) contains an improper encoding or escaping of output flaw (CWE-116) in its handling of user-supplied files. An attacker who already has authenticated access to the system can trigger it by supplying a crafted file, because the file's contents are not properly escaped before being processed. Successful exploitation yields arbitrary command execution with root privileges, giving the attacker full control of the SD-WAN management platform. Organizations running Cisco Catalyst SD-WAN Manager/vManage to manage their SD-WAN fabric are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-09, indicating active exploitation, though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply the fixed release per Cisco's security advisory (specific fixed versions are not included in the available data), and prioritize this patch given the KEV listing. Because the flaw requires authenticated local access, restrict management-plane access to trusted administrators and networks, review privileged accounts on the manager, and audit the system for unexpected processes or changes. Federal agencies must follow the KEV required action under BOD 22-01 (mitigate per vendor instructions or discontinue use).

7.825% KEV
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
largeon the order of tens of thousands of deployments worldwide
CVE-2026-20262
Authenticated Path Traversal File Overwrite in Cisco Catalyst SD-WAN Manager

CVE-2026-20262 is a directory/path traversal vulnerability (CWE-22) in Cisco Catalyst SD-WAN Manager, the central management component of Cisco's enterprise SD-WAN solution. An authenticated, remote attacker can supply crafted input containing traversal sequences that escape the intended directory, allowing the attacker to create a new file or overwrite any file on the affected system's filesystem. Overwriting arbitrary files can enable configuration tampering, persistence, or privilege escalation on the management appliance depending on which file is targeted. Any organization running Cisco Catalyst SD-WAN Manager is affected, with greatest risk where the management interface is reachable by broad user populations or from the internet. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-15, indicating exploitation in the wild; no public proof-of-concept is known, ransomware association is unknown, CVSS is not yet scored, and EPSS assigns a 28.2% probability of exploitation within 30 days (98th percentile).

Do: Apply the fixed release per Cisco's advisory (specific fixed versions are not provided in this data set, so consult Cisco's security notice) and follow CISA's KEV required action, including BOD 26-04 timelines for federal agencies and cloud service use. Until patched, restrict access to the SD-WAN Manager management interface to trusted management networks, enforce strong authentication, and audit the filesystem for unexpectedly created or recently modified files that could indicate exploitation. Evaluate each instance's internet exposure and prioritize internet-reachable management appliances for immediate remediation.

6.528% KEV
  • Cisco Catalyst SD-WAN Manager
largetens of thousands of enterprise management deployments (roughly 10k-100k systems)
Full article712 words · extracted from helpnetsecurity.com · click to collapse

Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers.

But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question of how attackers came to exploit it before Cisco had disclosed it publicly.

The vulnerability (CVE-2026-20262)

Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) is the management plane for the entire Cisco SD-WAN fabric.

CVE-2026-20262 is a path traversal flaw in the solution’s web user interface that can be exploited by sending a crafted HTTP request to an affected API endpoint of the affected system.

“A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least write access,” Cisco explained.

Like CVE-2026-20245 before it, CVE-2026-20262 stems from insufficient validation of user-supplied input and affects all Catalyst SD-WAN Manager deployment types: on-prem, Cloud-Pro, Cloud (Cisco Managed), and for Government (FedRAMP).

When Cisco disclosed CVE-2026-20245 nearly two weeks ago, they were still working on patches for it. The company released all of the fixed software versions by June 12.

The list of Cisco Catalyst SD-WAN releases that contain the fix for CVE-2026-20262 is identical to the one of releases that contain the fix for CVE-2026-20245. It’s unclear whether Cisco was simultaneously working on fixes for both, or whether the fix for CVE-2026-20245 also happens to plug the CVE-2026-20262 hole.

Help Net Security has reached out to Cisco with questions about the patches and the circumstances of the vulnerability’s discovery, and we’ll update this article when we hear back.

Indicators of compromise and remediation

Cisco has advised that customers upgrade to a fixed software release.

Those that have Cisco Catalyst SD-WAN Manager systems and ports exposed to the internet can search their log files for specific indicators of compromise (detailed in the advisory).

The indicators of compromise point to attackers abusing CVE-2026-20262 to drop a malicious file with a .war extension, and vManage’s WildFly Java application server deploying it as a Java web application accessible via the web server.

Attackers have been spotted interacting with it by sending commands via POST requests.

Cisco noted that it’s possible that some of these specific log entries might not consistently appear in every incident log, but that their presence “provides insight into what an attacker can do after initial compromise, such as deploy malicious code and interact with it.”

Sustained attacks on Cisco SD-WAN

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Monday, and ordered US federal civilian agencies to address it by June 29, 2026.

The 14-days-long remediation period is consistent with the requirements laid out in CISA’s new Binding Operational Directive, which orders agencies to prioritize security updates based on risk.

Since the beginning of this year, Cisco has released fixes for a handful of Catalyst SD-WAN Manager vulnerabilities that attackers have been exploiting as zero- or n-days:

Whether all of these vulnerabilities have been leveraged by the same threat group remains unknown, but the sustained, methodical focus on the platform suggests a determined adversary with deep familiarity with Cisco’s SD-WAN architecture.

UPDATE (June 17, 2026, 04:40 a.m. ET):

“On June 15, 2026, Cisco released software fixes to address a vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. Details are outlined in our security advisory. Cisco strongly recommends customers upgrade to a fixed software release. Customers needing assistance should contact Cisco Technical Assistance Center (TAC),” a Cisco Spokesperson told Help Net Security.

“The fix for both CVE-2026-20262 and CVE-2026-20245 is the same. The difference in disclosure timing is based on when Cisco became aware of active exploitation for each vulnerability, as outlined in the security advisories. We strongly recommend customers upgrade to the fixed software releases to address these vulnerabilities.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/16/cisco-sd-wan-cve-2026-20262-exploited/