CISCO Security Advisory

Published Date: June 15, 2026

CVE: CVE-2026-20262

Advisory Summary

❗️⚠️ Critical Security Update: Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability ⚠️❗️

A medium-severity vulnerability (CVE-2026-20262) has been identified in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw allows an authenticated remote attacker with at least low-privileged user access to upload a specially crafted file and create or overwrite any file on the system’s filesystem. Successful exploitation could potentially lead to root privilege escalation.

The root cause is improper validation of user-supplied input during the file upload process via an affected API endpoint. This exposes critical Cisco SD-WAN infrastructures to risks such as unauthorized modification or implantation of malicious files — a significant concern in enterprise network environments relying heavily on SD-WAN technologies for secure, flexible connectivity.

Cisco has promptly released software updates that fully remediate this vulnerability. No viable workarounds exist, making rapid patch deployment essential to mitigate potential exploitation.

For organizations deploying Cisco Catalyst SD-WAN Manager, prioritizing this update is crucial to maintain network security integrity and prevent attackers from leveraging this arbitrary file write vulnerability.

-WAN

Reference: Vendor Advisory