CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20262
Advisory Summary
📅 Published: June 15, 2026
❗️⚠️ Alert: Critical File Write Vulnerability in Cisco Catalyst SD-WAN Manager ⚠️❗️
A medium-severity vulnerability (CVE-2026-20262) has been identified in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow an authenticated remote attacker with valid write-level credentials to arbitrarily create or overwrite files on the system filesystem. The root cause is improper validation of user input during file uploads, enabling exploitation via crafted HTTP requests to API endpoints. Such unauthorized file manipulation could be leveraged to escalate privileges up to root on the affected system.
This vulnerability exposes SD-WAN infrastructure to significant risks including persistent compromise and unauthorized control unless addressed promptly. Cisco has released software updates that fully remediate the issue; no viable workarounds are currently available. Network and security teams managing Cisco Catalyst SD-WAN deployments should urgently apply the provided patches to ensure protection against exploitation.
Stay vigilant in monitoring your SD-WAN manager environments and confirm the deployment of Cisco’s security updates.
-WAN -2026-20262
Reference: Vendor Advisory