• News/
  • bleepingcomputer-20260615171242

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 15, 2026
·
Updated

Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard. The now-patched zero-day security flaw affects all deployment types, regardless of device configuration, including on-prem deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). Cisco said the issue stems from insufficient validation of user-supplied input during file uploads, which can allow low-privilege remote attackers to execute arbitrary commands as root by sending crafted HTTP requests to an affected API endpoint. "A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in a Monday advisory. "An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root." Cisco said its Product Security Incident Response Team (PSIRT) became aware of the exploitation of CVE-2026-20262 earlier this month and "s...

Read full article

Affected Software

4 affected components
Cisco Catalyst SD-WAN Manager (On-Prem Deployment)
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN Cloud-Pro)
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN Cloud (Cisco Managed))
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN for Government (FedRAMP))

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security update released by Cisco to fix a vulnerability in the Catalyst SD-WAN Manager that was exploited in zero-day attacks.

2

What security implications are discussed in the article?

The article highlights a vulnerability, tracked as CVE-2026-20262, that allows attackers to escalate privileges to root level, posing significant security risks.

3

Which products are affected by the vulnerability mentioned in the article?

The vulnerability affects multiple versions of Cisco Catalyst SD-WAN Manager, including On-Prem Deployment and various Cisco SD-WAN Cloud options.

4

How does the vulnerability impact network management?

The vulnerability can lead to unauthorized access and control over SD-WAN devices managed by the affected software, jeopardizing network integrity.

5

When was the vulnerability first exploited according to the article?

The vulnerability was exploited in attacks as early as June 17, 2026, shortly after the article was published.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203