logo

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

ID: a5f6b913-a940-5d95-b791-dd66c0dc2e5c

STIX ID: report--a5f6b913-a940-5d95-b791-dd66c0dc2e5c

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Sergiu Gatlan

...
...

Cisco disclosed and patched a zero-day in Catalyst SD-WAN Manager (CVE-2026-20262) that was actively exploited to escalate to root by abusing insufficient validation of uploaded files; affected deployments include on-prem, Cisco-managed cloud, and government FedRAMP environments. Cisco's PSIRT warned customers, provided fixed releases per version, and released IOCs (noting attempts to upload index.jsp and .war files) while urging immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.