An authenticated attacker can create or overwrite arbitrary files on affected systems, and exploitation in the wild has already been confirmed.
Summary
- CVE-2026-20262 is a directory traversal vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage) that allows an authenticated remote attacker to write or overwrite files on the filesystem.
- CISA has added the flaw to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in zero-day attacks.
- Federal agencies operating under BOD 26-04 must apply vendor mitigations or discontinue use of the product by 29 June 2026.
- Internet-exposed SD-WAN Manager instances represent the highest-priority exposure and must be assessed immediately.
- Cisco has released patches; organisations should review vendor guidance and conduct forensic triage where exploitation cannot be ruled out.
What has been disclosed
Cisco Catalyst SD-WAN Manager — the centralised management plane for Cisco’s SD-WAN fabric, formerly known as vManage — contains a directory or path traversal vulnerability tracked as CVE-2026-20262. The flaw allows an authenticated, remote attacker to create new files or overwrite existing files anywhere on the filesystem of an affected system. The practical consequence is that a threat actor who has already obtained valid credentials, or who has compromised a lower-privileged account, can move toward full system compromise by manipulating critical system files.
Exploitation confirmed
CISA’s decision to add CVE-2026-20262 to the Known Exploited Vulnerabilities catalogue reflects confirmed exploitation in the wild. Reporting from The Register and BleepingComputer indicates the vulnerability was exploited as a zero-day — meaning attacks were underway before a patch was publicly available. Zero-day exploitation of a network management platform elevates the risk profile considerably, as SD-WAN Manager typically sits at the heart of an organisation’s wide-area network topology and holds credentials, routing policy, and configuration data for the entire SD-WAN estate.
Scope and exposure considerations
SD-WAN Manager is commonly deployed in both on-premises and cloud-hosted configurations. CISA’s required action specifically notes that stakeholders must evaluate each asset’s internet exposure individually. Instances accessible directly from the internet carry the greatest immediate risk, but even internally-hosted deployments warrant attention given that the vulnerability requires only authenticated access — a condition that is not a particularly high bar if credentials have been phished, reused, or are held by a compromised third party.
Regulatory context
Under CISA’s Binding Operational Directive 26-04, federal civilian executive branch agencies are required to apply mitigations in accordance with Cisco’s vendor instructions by 29 June 2026, or discontinue use of the product if mitigations cannot be applied. The directive also introduces forensic triage requirements, meaning affected agencies are not simply expected to patch and move on — they must assess whether exploitation has already occurred. While BOD 26-04 applies directly to federal agencies, it represents a reasonable baseline for any organisation operating critical infrastructure or managing sensitive networks.
Cisco’s response
Cisco has released patches addressing the vulnerability. Organisations should consult Cisco’s official security advisory for version-specific remediation guidance, supported upgrade paths, and any available workarounds. The sources do not detail interim mitigations beyond applying the vendor’s fix or discontinuing use, so patch deployment should be treated as the primary remediation action.
Why it matters
SD-WAN Manager is not a peripheral system — it is the administrative control plane for an organisation’s entire SD-WAN deployment. Arbitrary file write capability on this platform, even when authenticated access is a prerequisite, is a serious risk. An attacker with a foothold in the management plane can alter routing policy, extract configuration secrets, or prepare persistent access that survives patching. The confirmed zero-day exploitation history means the threat is not theoretical, and forensic investigation should accompany any remediation effort. CISOs should treat this as a potential indicator of broader network compromise, not simply a software update to schedule.
What to do now
- Identify all instances of Cisco Catalyst SD-WAN Manager in your environment, including cloud-hosted deployments, and document their internet exposure.
- Apply Cisco’s vendor-supplied patches in accordance with the official security advisory as the primary remediation action.
- Where patching cannot be completed before the 29 June 2026 deadline, consider whether discontinuing use of the affected product is appropriate.
- Conduct forensic triage on SD-WAN Manager instances to assess whether exploitation has already occurred, consistent with CISA’s forensic triage requirements under BOD 26-04.
- Review access logs and authentication records for SD-WAN Manager for anomalous activity, particularly unexpected file creation or modification events.
- Assess whether any SD-WAN Manager credentials may have been exposed and consider credential rotation as part of the incident response process.
