AI Stories on SHORT INFO are generated & curated with AI
unverified 20 Jun, 02:10

Cisco Catalyst SD-WAN Manager vManage zero-days CVE-2026-20262 CVE-2026-20245 root file-write

Any organization running Cisco Catalyst SD-WAN Manager is exposed to live attacks right now. Cisco $CSCO confirmed two zero-days under exploitation: CVE-2026-20262 overwrites any file via the API, CVE-2026-20245 runs commands as root with no patch yet. CISA set a June 29 federal

Every organization that runs Cisco Catalyst SD-WAN Manager is exposed to active attacks right now. Cisco $CSCO has confirmed that two separate zero-day vulnerabilities in the product are being exploited in the wild, and one of them still has no patch. The first flaw, tracked as CVE-2026-20262, is an arbitrary file write issue. By sending specially crafted requests to an API endpoint, an attacker can create or overwrite any file on the underlying system. According to Cisco, it affects every deployment type, from on-premises installations to the cloud-managed versions and even the FedRAMP-authorized build used by US government agencies. CISA has added it to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate it by June 29. The second flaw, CVE-2026-20245, is a command injection vulnerability rated 7.8 in severity. It allows an attacker to run arbitrary commands as the root user and escalate privileges. Cisco has not yet released a fix or a workaround for this one, leaving exposed systems without a clear defensive option beyond restricting access. SD-WAN managers sit at the center of a network, controlling traffic across branch offices and data centers. Compromise at that layer gives an attacker broad reach, which is what makes these flaws more serious than an isolated endpoint bug. This is also the eighth Cisco SD-WAN vulnerability whose exploitation has been detected this year, a pattern that points to sustained attacker interest in network management infrastructure. Administrators who cannot patch immediately should limit who can reach the management interface and watch for unexpected file changes or new processes running with elevated privileges.

Published on
BlueskyFacebookXThreads