Back to advisories

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco Catalyst SD-WAN Manager has a file write vulnerability (CVE-2026-20262) being actively exploited in the wild. Authenticated attackers can create or overwrite files, leading to privilege escalation. Federal agencies are mandated to patch immediately; all organizations running SD-WAN Manager are at risk.

HIGHAdvisoryJun 16, 2026
Action required
Identify all Catalyst SD-WAN Manager instances in your environment and apply Cisco's latest security patch immediately. If patching is delayed, implement network-level access controls to restrict SD-WAN Manager to trusted administrators only.
Affected products
Catalyst SD-WAN ManagerCisco