logo

CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Under Active Targeted Exploitation

ID: f3b3a6a2-d434-58c7-a809-bd045b31c3e2

STIX ID: report--f3b3a6a2-d434-58c7-a809-bd045b31c3e2

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Pierluigi Paganini

...
...

Cisco confirmed that CVE-2026-20262, an arbitrary file-write vulnerability in the web UI of Catalyst SD-WAN Manager (formerly SD‑WAN vManage, CVSS 6.5), is being actively exploited in limited, targeted attacks. The flaw allows an authenticated low-privilege user to create or overwrite files via a crafted HTTP request, which could be used to escalate to root; Cisco PSIRT observed exploitation since June 2026 and CISA added the issue to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 29, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.