Catalyst SD-WAN Manager actively exploited (CVE-2026-20262)
CVE-2026-20262
CVE-2026-20262: Cisco Catalyst SD-WAN Manager file overwrite flaw actively exploited. Low-privilege users can create OS files to escalate to root. Patch or restrict API access.
Actively exploited in the wild - CVE-2026-20262 is a medium file-overwrite vulnerability in Cisco Catalyst SD-WAN Manager that lets authenticated attackers with low privileges create or overwrite any file on the system, escalating to root.
Overview
CVE-2026-20262 affects the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). The vulnerability stems from inadequate input validation during a file upload process. An authenticated, remote attacker with a low-privileged, single-task user account can send a crafted HTTP request to a vulnerable API endpoint, creating or overwriting arbitrary files on the underlying operating system. The attacker can then use this file write to escalate privileges to root, gaining full control of the system. Cisco has not yet released a patch; CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in attacks.
Impact
Successful exploitation compromises the integrity and availability of the affected Catalyst SD-WAN Manager instance. Attackers can plant malicious binaries, modify configuration files, or inject cron jobs directly into the OS filesystem. In an enterprise SD-WAN deployment, this could allow lateral movement into the broader network.
Remediation
No official patch is available as of this writing. Organizations should take the following steps:
- Restrict API access - Limit the vulnerable web UI and API endpoints to trusted management subnets only.
- Apply principle of least privilege - Audit and remove unnecessary single-task user accounts.
- Monitor for anomalous file operations - Configure endpoint detection and response (EDR) or file integrity monitoring (FIM) on the SD-WAN Manager OS.
- Check CISA KEV catalog - Review for any vendor-issued workarounds.
For ongoing threat context, see the Weekly Threat Roundup: Ivanti & Chrome Zero-Days (June 8-14), CISA adds Cisco, Chrome flaws to KEV catalog, and Weekly Threat Roundup: Cisco SD-WAN Zero-Day Under Attack (May 11-17).
Security Insight
This vulnerability underscores a recurring pattern in Cisco’s SD-WAN product line: API-level input validation gaps that grant file-write primitives to low-privilege users. It echoes the 2023 Catalyst SD-WAN Manager arbitrary file-write flaws that were also exploited before patches arrived. The active exploitation of CVE-2026-20262 suggests threat actors are systematically targeting network management planes as a high-value pivot point. Until Cisco ships a fix, defenders must treat the management API as a critical attack surface.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchroniza...
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or St...
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Han...
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insuffici...