Cisco patches actively exploited SD‑WAN Manager zero‑day vulnerability
Cisco released security updates for the Catalyst SD‑WAN Manager (formerly SD‑WAN vManage) to fix a zero‑day flaw tracked as CVE‑2026‑20262. The vulnerability, located in the web UI file‑upload function, allows an authenticated low‑privilege attacker to overwrite files and elevate to root privileges. Cisco confirmed that the bug has been exploited in the wild and urged customers to upgrade to the patched software releases.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities catalog and gave federal agencies a two‑week deadline to apply the fix. The flaw affects all deployment types, including on‑prem, cloud‑based, and government‑hosted SD‑WAN instances. Cisco also provided indicators of compromise for administrators to check logs for attempted uploads of malicious files.