INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Exploited
| 2026-06-16 10:53 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat actor is highly targeted, with limited exploitation of the vulnerability in recent attacks. The Cisco Catalyst SD-WAN issue has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), requiring affected systems to be upgraded to a patched software version by June 29, 2026.
Technical Mitigations AI-generated
* Implement input validation and sanitization for user-supplied data, particularly when it comes to file uploads, to prevent arbitrary file writes.
* Regularly update and patch operating systems, network devices, and software applications to ensure they have the latest security fixes and patches.
* Use secure protocols (e.g., HTTPS) for remote access and communication with affected systems to prevent unauthorized access or data exfiltration.
* Limit privileges and access rights of users and services running on affected systems to prevent further compromise or escalation of vulnerabilities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
sc•••••.log
su•••••.war
vm•••••.log
in•••••.jsp
ma•••••.csv
vc•••••.sh
20.9.•••.•••
20.12.•••.•••
20.9.•••.•••
20.12.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20245CVE-2026-20245
CVE-2026-20128CVE-2026-20128
CVE-2026-20127CVE-2026-20127
CVE-2026-20133CVE-2026-20133
CVE-2026-20182CVE-2026-20182
CVE-2022-20775CVE-2022-20775
CVE-2026-20262CVE-2026-20262
CVE-2026-20122CVE-2026-20122
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026/05/06
Threat actors exploited a recently disclosed Cisco SD-WAN zero-day vulnerability in the Catalyst SD-WAN Controller.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20182
Security patches not yet available
Last month, Cisco also
tagged a maximum severity Catalyst SD-WAN Controller authentication bypass flaw
(CVE-2026-20182) as actively exploited as a zero-day to gain administrative privileges on unpatched devices.
organisation
Catalyst SD-WAN Controller
Security patches not yet available
Last month, Cisco also
tagged a maximum severity Catalyst SD-WAN Controller authentication bypass flaw
(CVE-2026-20182) as actively exploited as a zero-day to gain administrative privileges on unpatched devices.
May 14
Threat actors exploited a zero-day vulnerability in Cisco's SD-WAN software, targeting systems with the CVE-2026-20182 patch.
Click on any entity below to view its context and source!
organisation
CVE-2026-20245
While Cisco has not yet released patches for CVE-2026-20245, it advised customers to upgrade to the software fixed for CVE-2026-20182 on May 14.
vulnerability
CVE-2026-20182
While Cisco has not yet released patches for CVE-2026-20245, it advised customers to upgrade to the software fixed for CVE-2026-20182 on May 14.
2026/05/16
Threat actors exploited a maximum-severity CVE-2026-20182 zero-day flaw in Cisco Catalyst SD-WAN Controllers to gain admin privileges on unpatched devices.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20182
Last month, it also tagged a
maximum-severity Catalyst SD-WAN Controller authentication-bypass flaw
(CVE-2026-20182) as actively exploited as a zero-day to gain admin privileges on unpatched devices.
organisation
Catalyst SD-WAN Controller
Last month, it also tagged a
maximum-severity Catalyst SD-WAN Controller authentication-bypass flaw
(CVE-2026-20182) as actively exploited as a zero-day to gain admin privileges on unpatched devices.
2026/06/09
Threat actors exploited a Cisco Catalyst SD-WAN zero-day vulnerability, CVE-2026-20245.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20245
Last week, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Cisco Catalyst SD-WAN issue, tracked as
CVE-2026-20245
(CVSS score v4.0 of 7.1), to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
CVSS
Last week, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Cisco Catalyst SD-WAN issue, tracked as
CVE-2026-20245
(CVSS score v4.0 of 7.1), to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
Known Exploited
Last week, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Cisco Catalyst SD-WAN issue, tracked as
CVE-2026-20245
(CVSS score v4.0 of 7.1), to its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1588.006 - Vulnerabilities
Last week, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Cisco Catalyst SD-WAN issue, tracked as
CVE-2026-20245
(CVSS score v4.0 of 7.1), to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
KEV
Last week, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Cisco Catalyst SD-WAN issue, tracked as
CVE-2026-20245
(CVSS score v4.0 of 7.1), to its
Known Exploited Vulnerabilities (KEV) catalog
.
Jun 16, 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco's SD-WAN software to target organizations.
2026/06/16
A successful attack could enable further privilege escalation to root.
Click on any entity below to view its context and source!
organisation
VulnCheck
The company said it is “not aware of successful exploitation by other means,” adding that it “observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.”
Landon Rice, senior exploit developer at VulnCheck, said the need for existing privileges “makes an attacker heavily reliant on previous vulnerabilities, or a net-new initial access vector, in order to be able to reach the privilege escalation path.”
organisation
CVE-2026-20245
Cisco warns of a privilege escalation flaw, tracked as CVE-2026-20245 (CVSS base score of 7.8), in Cisco Catalyst SD-WAN Manager, the platform formerly known as SD-WAN vManage.
organisation
SD-WAN vManage
Cisco warns of a privilege escalation flaw, tracked as CVE-2026-20245 (CVSS base score of 7.8), in Cisco Catalyst SD-WAN Manager, the platform formerly known as SD-WAN vManage.
"
Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco
said
in an advisory.
“A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.”
reads the advisory
.
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks.
organisation
the Cisco Catalyst SD-WAN
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as
CVE-2026-20245
) actively exploited in attacks enabling root privilege escalation.
The validation error defect affecting the Cisco Catalyst SD-WAN Manager allows authenticated or local attackers to execute commands as root, resulting in command-injection attacks on an affected system, the company said.
organisation
CVE-2026
CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Under Active Targeted Exploitation.
organisation
Catalyst SD-WAN
CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Under Active Targeted Exploitation
Cisco warned that CVE-2026-20262, a Catalyst SD-WAN Manager vulnerability allowing arbitrary file writes, is being actively exploited.
Ravie Lakshmanan
Jun 16, 2026
Vulnerability / Network Security
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
In February, Cisco patched another Catalyst SD-WAN Manager information disclosure security flaw (CVE-2026-20133), flagged
as actively exploited
in late April, and, two weeks later, warned of two more flaws (CVE-2026-20128 and CVE-2026-20122)
that were abused in the wild
.
"
Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
organisation
CVE-2026-20262
CVE-2026-20262 (CVSS score of 6.5) is an arbitrary file write vulnerability in the web interface of Cisco Catalyst SD-WAN Manager.
organisation
Cisco Catalyst SD-WAN
CVE-2026-20262 (CVSS score of 6.5) is an arbitrary file write vulnerability in the web interface of Cisco Catalyst SD-WAN Manager.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco
said
in an advisory.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in a
Monday advisory
.
The vulnerability affects Cisco Catalyst SD-WAN Manager across all deployment models, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud deployments, and FedRAMP environments.
Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," the company added, advising admins first to generate an admin-tech file to help with the review.
organisation
CVSS
The vulnerability, tracked as
CVE-2026-20262
, carries a CVSS score of 6.5 out of 10.0.
organisation
Cisco SD-WAN
The follow-on activities related to this vulnerability are -
CVE-2026-20262 is the
eighth security flaw
impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
Other vulnerabilities in Cisco SD-WAN discovered this year are
CVE-2026-20122
,
CVE-2026-20127
,
CVE-2026-20128
,
CVE-2026-20133
,
CVE-2022-20775
, and
CVE-2026-20182
.
Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet.
organisation
CVE-2022
The follow-on activities related to this vulnerability are -
CVE-2026-20262 is the
eighth security flaw
impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775.
Other vulnerabilities in Cisco SD-WAN discovered this year are
CVE-2026-20122
,
CVE-2026-20127
,
CVE-2026-20128
,
CVE-2026-20133
,
CVE-2022-20775
, and
CVE-2026-20182
.
Below are the flaws added to the catalog:
CVE-2022-20775
Cisco Catalyst SD-WAN Path Traversal Vulnerability
CVE-2026-20127
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Cisco SD-WAN)
organisation
Product Security Incident Response Team
"
Cisco said its Product Security Incident Response Team (PSIRT) became aware of the exploitation of CVE-2026-20262 earlier this month and "strongly" advised customers to patch their systems.
Cisco's Product Security Incident Response Team (PSIRT) became aware of CVE-2026-20245 exploitation in June after Google Cloud cybersecurity subsidiary Mandiant reported the flaw but did not share any details.
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Jun 16, 2026
Vulnerability / Network Security
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
infrastructure
6,000 WAN devices
"
Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard.
organisation
UI
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco
said
in an advisory.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in a
Monday advisory
.
“A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.”
reads the advisory
.
organisation
Cisco
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in a
Monday advisory
.
Cisco said exploitation of a pair of zero-days it disclosed earlier this year —
CVE-2026-20182
or
CVE-2026-20127
— could allow attackers the access required to exploit the new vulnerability.
In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root.
organisation
Cisco SD-WAN Cloud-Pro
The vulnerability affects Cisco Catalyst SD-WAN Manager across all deployment models, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud deployments, and FedRAMP environments.
organisation
the Cisco TAC
Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," the company added, advising admins first to generate an admin-tech file to help with the review.
organisation
Cisco SD-WANs
The Cybersecurity and Infrastructure Security Agency has added seven vulnerabilities affecting
Cisco SD-WANs and firewalls
to its known exploited vulnerabilities catalog this year, not including CVE-2026-20245, which has yet to be added to the catalog.
organisation
SD-WAN
Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet
Cisco warns of CVE-2026-20245 in SD-WAN Manager, a flaw that can lead to root access via file upload command injection; no patch or workaround yet.
Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard.
Cisco customers encounter another SD-WAN zero-day under attack.
Cisco warns of unpatched SD-WAN zero-day exploited in attacks.
organisation
Google
Cisco's Product Security Incident Response Team (PSIRT) became aware of CVE-2026-20245 exploitation in June after Google Cloud cybersecurity subsidiary Mandiant reported the flaw but did not share any details.
organisation
SecurityAffairs
Below are the flaws added to the catalog:
CVE-2022-20775
Cisco Catalyst SD-WAN Path Traversal Vulnerability
CVE-2026-20127
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Cisco SD-WAN)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CISCO Catalyst SD-WAN)
organisation
Catalyst
Below are the flaws added to the catalog:
CVE-2022-20775
Cisco Catalyst SD-WAN Path Traversal Vulnerability
CVE-2026-20127
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Cisco SD-WAN)
organisation
API
An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system.
An attacker could exploit this behavior to create or overwrite any file on the underlying operating system by sending crafted HTTP requests to an affected API endpoint.
Cisco said the issue stems from insufficient validation of user-supplied input during file uploads, which can allow low-privilege remote attackers to execute arbitrary commands as root by sending crafted HTTP requests to an affected API endpoint.
infrastructure
20.9.9
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
infrastructure
20.12.7
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
infrastructure
20.15.4
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
infrastructure
20.15.5
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
infrastructure
20.18.3
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
infrastructure
26.1.1
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
organisation
Cisco Catalyst SD-
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
organisation
Cisco Releases Security Updates
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw.
organisation
APT
The exploitation of some of these flaws has been attributed to an advanced persistent threat (APT) actor named UAT-8616.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
Mandiant
The company disclosed the vulnerability, which was first spotted by Mandiant, on Thursday and warned that a security patch is not yet available and there are no workarounds to mitigate the defect in the meantime.
organisation
Cisco Technical Assistance Centers
The company encouraged customers that need help distinguishing between legitimate and malicious activity to contact Cisco Technical Assistance Centers.
organisation
vSmart
However, it shared indicators of compromise (IOCs) warning admins to check their SD-WAN /var/log/scripts.log file for attempts to upload tenant configuration data to vSmart controllers to escalate privileges through legitimate commands, as in the following example:
organisation
the Cisco Technical Assistance Center
“In such cases, follow the specific remediation steps that will be provided by the Cisco Technical Assistance Center (TAC) to help secure the system.”
organisation
TAC
“In such cases, follow the specific remediation steps that will be provided by the Cisco Technical Assistance Center (TAC) to help secure the system.”
June 29, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Cisco SD-WAN Zero-Day Exploit in its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by June 29, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the Cisco Catalyst issue to its
Known Exploited Vulnerabilities (KEV) catalog
ordering federal agencies to fix it by June 29, 2026.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.
attribution
Cisco Catalyst
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the Cisco Catalyst issue to its
Known Exploited Vulnerabilities (KEV) catalog
ordering federal agencies to fix it by June 29, 2026.
attribution
Known Exploited
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the Cisco Catalyst issue to its
Known Exploited Vulnerabilities (KEV) catalog
ordering federal agencies to fix it by June 29, 2026.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.
attribution
KEV
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
the Cisco Catalyst issue to its
Known Exploited Vulnerabilities (KEV) catalog
ordering federal agencies to fix it by June 29, 2026.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.
attribution
Federal Civilian Executive Branch
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.
attribution
FCEB
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.
June 2026
Threat actors exploited a zero-day vulnerability in Cisco Catalyst SD-WAN software.
Click on any entity below to view its context and source!
infrastructure
20.9.9
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
infrastructure
20.12.7
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
infrastructure
20.15.4
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
infrastructure
20.15.5
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
infrastructure
20.18.3
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
infrastructure
26.1.1
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
20.15.5.3
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
26.1.1.2
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
20.9.9.2
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
20.15.4.5
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
20.18.3.1
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
observable
20.12.7.2
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
organisation
Cisco Catalyst SD-WAN Release
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
organisation
Cisco Catalyst SD-
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
organisation
Cisco
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in June 2026, adding it was discovered during internal security testing.
Tactical Metrics
Metrics
infrastructure
20.9.9
Software Version
Click for context!
Patches have been released to address the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and ea…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
20.12.7
Software Version
…ress the issue -
Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier - Fixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisc…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
20.15.4
Software Version
…ixed in 20.9.9.2
Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier - Fixed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisc…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
20.15.5
Software Version
…xed in 20.12.7.2
Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier - Fixed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
20.18.3
Software Version
…xed in 20.15.4.5
Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "bec…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
26.1.1
Software Version
…d earlier - Fixed in 20.15.5.3
Cisco Catalyst SD-WAN Release 20.18.3 - Fixed in 20.18.3.1
Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier - Fixed in 26.1.1.2
Cisco said it "became aware of limited exploitation of this vulnerability" in J…
Cisco Catalyst SD-WAN Release
First Fixed Release
20.9.9.1 and earlier
20.9.9.2
20.12.7.1 and earlier
20.12.7.2
20.15.4.4 and earlier
20.15.4.5
20.15.5.2 and earlier
20.15.5.3
20.18.3
20.18.3.1
26.1.1.1 and earlier
26.1.1.2
Metrics
infrastructure
6,000
Wan Devices
Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard.
"
Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard.
Intelligence Sources
The Hacker News
2026-06-16
Security Affairs
2026-06-05
Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet
Security Affairs
BleepingComputer
2026-06-05
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
BleepingComputer
CyberScoop
2026-06-09
Security Affairs
2026-06-16
BleepingComputer
2026-06-15
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
38x
organisation
Identified Entity
CVE-2026
entity
12x
timeline
Temporal Reference
June 29, 2026
date
11x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
8x
vulnerability
Exploited CVE
CVE-2026-20262
cve
6x
infrastructure
Software Version
20.9.9
version
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
2x
general metric
Cisco Vulnerabilities
91
cisco vulnerabilities
2x
general metric
%
54
%
Contextual Telemetry
Context Block
8 METRICS
vulnerability
CVSS Score
6
score
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
industry
Targeted Sector
Government
sector
general metric
Jun
16
jun
infrastructure
Wan Devices
6,000
wan devices
general metric
Catalyst Cisco Catalyst Sd Wan Controller
20,775
catalyst cisco catalyst sd wan controller
general metric
Apr
15
apr
general metric
Vpn
0
vpn
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.