Cisco Discloses Second Exploited SD-WAN Vulnerability (CVE-2026-20262) in Two Weeks
Cisco's Product Security Incident Response Team (PSIRT) has confirmed the active exploitation of CVE-2026-20262, a critical path traversal vulnerability found in the Catalyst SD-WAN Manager. This flaw enables authenticated attackers to manipulate system files, potentially leading to root privilege escalation. The discovery of this vulnerability during internal security testing, despite its active exploitation, raises questions about the timeline of its public disclosure versus attacker awareness.
This incident follows closely on the heels of another recently exploited SD-WAN vulnerability, highlighting a concerning trend for Cisco's network management solutions. Both CVE-2026-20262 and its predecessor, CVE-2026-20245, stem from insufficient validation of user-supplied input and impact all deployment types of the Catalyst SD-WAN Manager, including on-premise, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP) environments.
In response to the active threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has promptly added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion triggers a Binding Operational Directive (BOD) 26-04, which mandates U.S. federal civilian agencies to address the vulnerability by June 29, 2026. CISA's directive emphasizes a risk-based approach to vulnerability management, prioritizing the rapid remediation of high-risk vulnerabilities, especially those in publicly exposed assets that could grant total control post-exploitation.
Cisco advises customers to upgrade to fixed software releases immediately. For those with internet-exposed Catalyst SD-WAN Manager systems, reviewing log files for specific indicators of compromise is crucial. Attackers have been observed using this vulnerability to drop malicious `.war` files, which are then deployed as Java web applications, allowing them to send commands via POST requests. The rapid response from CISA and Cisco underscores the severe implications of this vulnerability and the need for organizations to act swiftly to protect their networks.
Read original source