DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:01:53ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
UAC-0145 (Sandworm) CRITICAL — UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking… /// CYLINDRICALCANINE CRITICAL — CylindricalCanine is a newly named operational subgroup within the China-linked… /// @CrowdStrike CRITICAL — July 2026 Patch Tuesday analysis: CVE-2026-56155 (AD FS EoP, CVSS 7.8) confirmed… /// @MsftSecIntel CRITICAL — Microsoft has confirmed active exploitation of CVE-2026-56155 in Active Directory… /// @GossiTheDog CRITICAL — CVE-2026-56155 ADFS zero-day is nastier than the CVSS 7.8 suggests. Admin on your ADFS…
26Critical Threats
18Active CVEs
10IOCs Tracked
5New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20262PUBLISHED: 2026-06-15
MEDIUMCVE-2026-20262★ CISA KEV LISTED

Cisco Catalyst SD-WAN Manager Arbitrary File Write / Path Traversal (Zero-Day, KEV)

VENDOR: Cisco//PRODUCT: Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
6.5
MEDIUM
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

A path traversal (CWE-22) vulnerability in the Catalyst SD-WAN Manager web UI allows an authenticated attacker with at least write-level credentials to send a crafted HTTP request to an affected API endpoint, writing or overwriting arbitrary files on the underlying operating system — including deploying malicious WAR files via the WildFly application server to escalate to root. Cisco observed limited in-the-wild exploitation as a zero-day before patch release in June 2026, attributed with medium confidence to APT actor UAT-8616, the eighth Cisco SD-WAN zero-day of 2026 in a sustained campaign targeting SD-WAN control planes. CISA added to KEV on June 15, 2026 with a June 29, 2026 federal remediation deadline (today); no workaround exists — upgrade is the only fix. The CVSS score of 6.5 understates real-world risk: compromising the SD-WAN management plane can affect thousands of downstream edge devices.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
UNCHANGED
C:N · I:H · A:N
AFFECTED VERSIONSAll Cisco Catalyst SD-WAN Manager deployment types (on-prem, Cloud-Pro, Cloud Cisco Managed, FedRAMP) — all versions prior to Cisco's first fixed releases per branch; identical fix list to CVE-2026-20245
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html
  • https://securityaffairs.com/193693/security/cve-2026-20262-cisco-catalyst-sd-wan-flaw-under-active-targeted-exploitation.html
  • https://threat-modeling.com/cve-2026-20262-cisco-catalyst-sd-wan-manager-path-traversal-cisa-kev/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn