Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw β€” Cybersecurity | Versia.media

Cisco has released security patches for a medium-severity vulnerability in Catalyst SD-WAN Manager that is now being actively exploited in the wild.

The flaw, identified as CVE-2026-20262, holds a CVSS score of 6.5 out of 10.0.

"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco stated in an advisory.

The networking equipment vendor noted that the issue arises from insufficient validation of user-provided input during a file upload process. An attacker could take advantage of this behavior to create or overwrite any file on the underlying operating system by sending specially crafted HTTP requests to a vulnerable API endpoint.

This could then be leveraged to escalate privileges to root. Nevertheless, successful exploitation depends on the attacker already possessing valid credentials with at least write access.

The vulnerability affects the following products, regardless of the deployment method:

- Cisco Catalyst SD-WAN Manager On-Prem - Cisco SD-WAN Cloud-Pro - Cisco SD-WAN Cloud (Cisco Managed) - Cisco SD-WAN for Government (FedRAMP)

Patches have been released to resolve the issue:

- Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2 - Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2 - Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5 - Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3 - Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1 - Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2

Cisco reported that it "became aware of limited exploitation of this vulnerability" in June 2026, adding that it was discovered through internal security testing.

The company has also provided indicators of compromise related to the malicious activity, urging customers to examine "/var/log/nms/vmanage-server.log" for suspicious WAR file uploads, as shown below:

Other indicators include attempts to deploy malicious code and interact with it, though Cisco cautioned that these may not "consistently appear" in every incident log. The follow-on activities associated with this vulnerability are:

/var/log/nms/vmanage-appserver.log: 11-June-2026 07:52:55,275 UTC INFO [server] (DeploymentScanner-threads - 2) WFLYSRV0010: Deployed "suspicious.war" (runtime-name : "suspicious.war")

/var/log/nms/containers/service-proxy/serviceproxy-access.log: [2026-06-11T07:57:33.635Z] "POST /suspicious/index.jsp HTTP/1.1" 200 - 267 76 17 - "1.1.1.54" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0" "d7336b83-422b-4000-93e1-0296f102bbed" "1.1.1.4:8443" "127.0.0.1:8080"

CVE-2026-20262 is the eighth security flaw affecting Cisco SD-WAN to be identified as actively exploited this year, following CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775. The exploitation of some of these flaws has been linked to an advanced persistent threat (APT) actor known as UAT-8616.

This development has led the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to implement the fixes by June 29, 2026.

← Cybersecurity