Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20262

Published 2026-06-15
Updated last month
Vendor/s
Cisco
Product/s
Catalyst SD-WAN Manager
Version/s
* > 20.9.9.2
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
6.5
/ 10
Medium
Severity Details
Base score
6.5 Medium
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Description

CVE-2026-20262 is a medium-severity file overwrite vulnerability in Cisco Catalyst SD-WAN Manager that allows authenticated attackers to gain root access.

CPE

Cisco logo
Cisco
Product Version Start Version End (excl.) Status
catalyst_sd-wan_manager * 20.9.9.2 vulnerable
catalyst_sd-wan_manager 20.10 20.12.7.2 vulnerable
catalyst_sd-wan_manager 20.13 20.15.4.5 vulnerable
catalyst_sd-wan_manager 20.15.5 20.15.5.3 vulnerable
catalyst_sd-wan_manager 20.16 20.18.3.1 vulnerable
catalyst_sd-wan_manager 26.1 26.1.1.2 vulnerable

Related weakness (CWE)

CWE-22

Remediation plan

1

Apply official patches

Cisco has released software updates to address this arbitrary file write vulnerability. Organizations should refer to the Cisco Security Advisory (cisco-sa-sdwan-arbfw-c2rZvQ) for the latest patch information and implementation details.

2

Update affected systems

Upgrade to fixed versions including 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2. Ensure all instances of Catalyst SD-WAN Manager (formerly vManage) are running a non-vulnerable software release.

3

Restrict access

Enforce the principle of least privilege by auditing user accounts and removing unnecessary access to the web UI. Use network access control lists (ACLs) or firewalls to restrict management interface access to authorized administrative subnets only.

4

Monitor for exploitation

Review system logs for unauthorized file system modifications and monitor API traffic for suspicious upload activity. Follow CISA’s Forensics Triage Requirements to identify potential indicators of compromise if exploitation is suspected.

Detection Guidance

"Monitor web management logs for unusual HTTP POST requests to API endpoints associated with file uploads. Look for directory traversal patterns (e.g., ../) in upload parameters. Audit the filesystem for unexpected files in system directories or modifications to sensitive configuration files. Additionally, track successful logins from low-privileged accounts followed by high-frequency API calls, as these may indicate an attempt to exploit the file-handling logic for privilege escalation."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management