Cisco confirms actively exploited SD-WAN Manager zero-day
Cisco $CSCO has confirmed a zero-day flaw in its Catalyst SD-WAN Manager that is being actively exploited in the wild. A low-privileged attacker can overwrite system files and escalate to full root control. Cisco says there are no workarounds, and upgrading is the only fix.
Cisco $CSCO has confirmed CVE-2026-20262, a zero-day in Catalyst SD-WAN Manager being exploited in real-world attacks. The flaw lets a low-privileged user write files anywhere via the management interface file upload feature, then escalate to root. It affects every deployment type, including on-premise systems, managed cloud, and the FedRAMP version used by government agencies. CISA added it to its known-exploited list and ordered federal agencies to patch by June 29. It is the eighth Cisco SD-WAN zero-day caught under active attack in 2026.