Cisco SD-WAN make-me-root bug under attack
ID: 0527ea1a-7ed0-595b-83d6-27e40b0619c6
STIX ID: report--0527ea1a-7ed0-595b-83d6-27e40b0619c6
Feed Name: The Register (Security)
Threat Score
Cisco issued patches for CVE-2026-20262, a Catalyst SD-WAN Manager web UI file-upload input-validation flaw that attackers are actively exploiting to create or overwrite files and potentially escalate to root if they possess valid credentials; CISA added it to its Known Exploited Vulnerabilities catalog and mandated rapid patching, and there are no workarounds — upgrading to fixed software is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
