San Jose, California-based Cisco has released an emergency security update to fix a critical zero-day vulnerability in its Catalyst SD-WAN Manager, formerly known as vManage, which the company confirms is being actively exploited in the wild. Tracked as CVE-2026-20262, the flaw stems from a critical weakness in the file upload process that allows unauthenticated or low-privileged attackers to send a crafted HTTP request to an API endpoint and write arbitrary files directly to the appliance’s underlying filesystem. By overwriting key system files, a remote attacker can escalate privileges to root, bypass standard authentication controls, and potentially seize full control of the network management system, posing a severe risk to corporate and government networks. The vulnerability affects all supported deployment models, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud environments, and FedRAMP-certified versions used to manage sensitive U.S. government communications and data. Cisco has released patches for multiple software versions, including Release 20.9.9.1, 20.12.7.1, 20.15.4.4, 20.15.5.2, and 20.18.3, and urges network administrators to apply the fixes immediately because no workarounds are available. Security agencies have elevated the flaw to a top-priority issue and advise organizations using the affected SD-WAN Manager to review network logs for unauthorized file modifications or suspicious API activity that could indicate compromise.
Prepared by Jonathan Pierce and reviewed by editorial team.
如果您使用思科的 SD-WAN Manager,您的网络将面临风险。攻击者可能会获得完全控制权,对您的数据构成严重威胁。请检查您的系统是否有未经授权的文件更改或可疑的 API 活动。请立即更新您的软件。
这是一个严重的漏洞,没有简单的解决办法。思科已为多个版本发布了紧急补丁。立即应用它们以保护您的网络。如果您认识使用思科 SD-WAN Manager 的人,值得转发。
源中未指定。
未在源中指定。
No left-leaning sources found for this story.
No right-leaning sources found for this story.
Comments