VULNERABILITY OVERVIEW
A path traversal (CWE-22) vulnerability in the Catalyst SD-WAN Manager web UI allows an authenticated attacker with at least write-level credentials to send a crafted HTTP request to an affected API endpoint, writing or overwriting arbitrary files on the underlying operating system — including deploying malicious WAR files via the WildFly application server to escalate to root. Cisco observed limited in-the-wild exploitation as a zero-day before patch release in June 2026, attributed with medium confidence to APT actor UAT-8616, the eighth Cisco SD-WAN zero-day of 2026 in a sustained campaign targeting SD-WAN control planes. CISA added to KEV on June 15, 2026 with a June 29, 2026 federal remediation deadline (today); no workaround exists — upgrade is the only fix. The CVSS score of 6.5 understates real-world risk: compromising the SD-WAN management plane can affect thousands of downstream edge devices.
CVSS BREAKDOWN
All Cisco Catalyst SD-WAN Manager deployment types (on-prem, Cloud-Pro, Cloud Cisco Managed, FedRAMP) — all versions prior to Cisco's first fixed releases per branch; identical fix list to CVE-2026-20245CITATIONS
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
- → https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- → https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html
- → https://securityaffairs.com/193693/security/cve-2026-20262-cisco-catalyst-sd-wan-flaw-under-active-targeted-exploitation.html
- → https://threat-modeling.com/cve-2026-20262-cisco-catalyst-sd-wan-manager-path-traversal-cisa-kev/