Cisco SD-WAN Zero-Day CVE-2026-20262: Active Root Exploit
Cisco has patched a critical zero-day vulnerability in its Catalyst SD-WAN Manager platform. The flaw, tracked as CVE-2026-20262, allows authenticated remote attackers to overwrite files and escalate to root privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 15, 2026, with a patching deadline of June 29.
What Happened: Cisco SD-WAN Manager Zero-Day Enables Root Takeover
Cisco disclosed CVE-2026-20262 on June 15, 2026, after its Product Security Incident Response Team confirmed active exploitation. The vulnerability affects the web UI of Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. An attacker with low-level authentication can send crafted HTTP requests to an API endpoint and create or overwrite any file on the underlying operating system.
Consequently, the attacker can plant a malicious file and later use it to elevate privileges to root. Cisco warned that all deployment types are vulnerable regardless of device configuration. This includes on-premises deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud, and Cisco SD-WAN for Government.
Technical Details of the CVE-2026-20262 Vulnerability
The vulnerability stems from insufficient validation of user-supplied input during file uploads. When an authenticated remote attacker sends a crafted HTTP request to an affected API endpoint, the system fails to properly restrict the upload path. Therefore, the attacker can write files to arbitrary locations on the filesystem.
Moreover, Cisco shared indicators of compromise to help defenders detect exploitation. Administrators should inspect logs on vmanage-server, vmanage-appserver, and serviceproxy-access for attempts to upload index.jsp and .war files. These file types are commonly used to deploy web shells or execute arbitrary code on Java-based application servers.
- CVE ID: CVE-2026-20262
- CVSS Severity: Critical (exact score pending from NVD)
- Attack Vector: Network
- Privileges Required: Low (authenticated)
- Impact: Arbitrary file write, root privilege escalation
- Affected Product: Cisco Catalyst SD-WAN Manager (vManage)
Business and Operational Impact
SD-WAN Manager is the central command plane for enterprise-wide network management. A single instance can manage up to 6,000 branch routers and edge devices. If an attacker gains root access, they can reconfigure routing policies, intercept traffic, or disable connectivity across the entire SD-WAN fabric.
In addition, the FedRAMP-authorized government variant is affected. This raises the stakes for federal agencies and contractors who must comply with CISA binding operational directives. Failure to patch by the June 29 due date could trigger compliance violations and expose sensitive government traffic.
- Enterprise Disruption: Complete loss of network management control
- Data Interception: Ability to read or modify routed traffic
- Compliance Risk: CISA BOD 26-04 mandates rapid patching for KEV entries
- Supply Chain Exposure: Compromised SD-WAN configs can propagate to managed endpoints
Mitigation and Recommendations
Cisco released security updates for multiple software trains. Organizations should upgrade to a fixed release immediately. Moreover, administrators should review logs for the published IOCs before and after patching to identify potential compromise.
Immediate Actions for Defenders
- Upgrade to the first fixed release for your deployment: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2.
- Inspect vmanage-server, vmanage-appserver, and serviceproxy-access logs for uploads of
index.jspor.warfiles. - Rotate all administrative credentials on the SD-WAN Manager if any IOCs are present.
- Restrict network access to the SD-WAN Manager web UI to trusted IP ranges until patching is complete.
- Enable centralized logging and alerting for file-upload events on the management plane.
Additional Guidance
If upgrading is not immediately possible, limit access to the management interface through firewall rules or jump hosts. Furthermore, organizations running cloud-managed deployments should verify that Cisco has applied the patch on their behalf. On-premises and government instances require manual intervention.
Bottom line: CVE-2026-20262 is under active exploit and carries a CISA KEV deadline of June 29, 2026. Patch Cisco Catalyst SD-WAN Manager today, hunt for IOCs in your logs, and treat any positive findings as a confirmed breach.
Incident Summary
| CVE ID / Incident: | CVE-2026-20262 — Cisco Security Advisory |
| Affected Systems: | Cisco Catalyst SD-WAN Manager (formerly vManage) — all deployment types including on-prem, Cloud-Pro, Cisco Managed, and FedRAMP |
| Disclosure Date: | June 15, 2026 |
| Patch Status: | Fixed releases available: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2 |
| CISA KEV Added: | June 15, 2026 (Due Date: June 29, 2026) |
| Ransomware Context: | Unknown at time of publication |
References
- Cisco, “Cisco Catalyst SD-WAN Manager File Upload Vulnerability,” Cisco Security Advisory, June 15, 2026, https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csdwan-manager-file-upload-20262, accessed June 15, 2026.
- BleepingComputer, “Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks,” June 15, 2026, https://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/, accessed June 15, 2026.
- CISA, “Known Exploited Vulnerabilities Catalog,” CVE-2026-20262 entry, June 15, 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, accessed June 15, 2026.