Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
ID: a5f6b913-a940-5d95-b791-dd66c0dc2e5c
STIX ID: report--a5f6b913-a940-5d95-b791-dd66c0dc2e5c
Feed Name: Bleeping Computer
Threat Score
Cisco disclosed and patched a zero-day in Catalyst SD-WAN Manager (CVE-2026-20262) that was actively exploited to escalate to root by abusing insufficient validation of uploaded files; affected deployments include on-prem, Cisco-managed cloud, and government FedRAMP environments. Cisco's PSIRT warned customers, provided fixed releases per version, and released IOCs (noting attempts to upload index.jsp and .war files) while urging immediate patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
