
Cisco has released security patches to resolve a vulnerability in the Catalyst SD-WAN Manager, identified as CVE-2026-20262, which has been leveraged in attacks to escalate privileges to root.
Previously referred to as SD-WAN vManage, this network management platform enables administrators to oversee up to 6,000 SD-WAN devices through a single interface.
The now-fixed zero-day security flaw impacts every deployment type, irrespective of device setup, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
According to Cisco, the problem arises from insufficient validation of user-supplied input during file uploads. This allows low-privilege remote attackers to execute arbitrary commands as root by sending specially crafted HTTP requests to a vulnerable API endpoint.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco stated in a Monday advisory.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root."
Cisco noted that its Product Security Incident Response Team (PSIRT) became aware of the exploitation of CVE-2026-20262 earlier this month and "strongly" urged customers to apply patches to their systems.
Although the company did not disclose specifics about these attacks, it provided indicators of compromise (IOCs), warning administrators to examine their SD-WAN vmanage-server, vmanage-appserver, and serviceproxy-access logs for signs of attempts to upload index.jsp and .war files.
In February, Cisco patched another Catalyst SD-WAN Manager information disclosure vulnerability (CVE-2026-20133), which was flagged as actively exploited in late April. Two weeks later, it alerted users to two additional flaws (CVE-2026-20128 and CVE-2026-20122) that were being abused in the wild.
Last month, it also marked a maximum-severity Catalyst SD-WAN Controller authentication-bypass flaw (CVE-2026-20182) as actively exploited as a zero-day to gain admin privileges on unpatched devices.
More recently, in early June, Cisco warned of another unpatched Catalyst SD-WAN Manager zero-day (CVE-2026-20245) that was exploited in attacks, enabling attackers to achieve root privileges.
Over the past several years, the Cybersecurity and Infrastructure Security Agency (CISA) has identified 91 Cisco vulnerabilities as abused in the wild, including five in Cisco Catalyst SD-WAN Manager and six others exploited in ransomware attacks.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
CISA flags new SD-WAN flaw as actively exploited in attacks
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges