logo

Cisco SD-WAN make-me-root bug under attack

ID: 0527ea1a-7ed0-595b-83d6-27e40b0619c6

STIX ID: report--0527ea1a-7ed0-595b-83d6-27e40b0619c6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-07-23

...
...

Cisco issued patches for CVE-2026-20262, a Catalyst SD-WAN Manager web UI file-upload input-validation flaw that attackers are actively exploiting to create or overwrite files and potentially escalate to root if they possess valid credentials; CISA added it to its Known Exploited Vulnerabilities catalog and mandated rapid patching, and there are no workarounds — upgrading to fixed software is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.