Saturday, 25 July 2026
Source ReportersIndependent journalism, worldwide

Tech

Cisco patches actively exploited flaw in SD-WAN management software

CVE-2026-20262 lets attackers escalate to root access via crafted file uploads on Catalyst SD-WAN Manager, and Cisco says it has already seen exploitation in the wild.

Cisco
Photo: Cisco via Wikimedia Commons (Public domain)

By Source Reporters Newsdesk

Fri, 24 July 2026 · 2 min read

Cisco has released a security patch for a vulnerability in its Catalyst SD-WAN Manager software that the company says has already been actively exploited by attackers to gain root-level access to affected systems.
The flaw, tracked as CVE-2026-20262, allows an attacker to escalate privileges to root through a crafted file upload, according to Cisco's advisory. SD-WAN Manager is the centralized administration console organizations use to configure and monitor software-defined wide-area networks — the systems many large enterprises rely on to manage traffic and security policy across branch offices, data centers and cloud environments. A successful exploit of the vulnerability could give an attacker full administrative control over the management platform, and by extension significant visibility into, or control over, the broader network infrastructure it oversees.
Cisco said the vulnerability affects all deployment types of the affected software, meaning organizations running the platform on-premises, in private cloud, or in Cisco-hosted environments are all potentially exposed until they apply the fix. The company has released updated software versions that close the flaw and is urging customers to patch immediately given the confirmation of in-the-wild exploitation, which significantly raises the urgency compared with vulnerabilities discovered only through internal testing or responsible disclosure.
Network management platforms like SD-WAN Manager are considered especially attractive targets for attackers because of the privileged position they occupy: compromising the management console can, in the worst case, give an intruder a foothold to pivot into the broader corporate network, intercept or reroute traffic, or disable security controls across many sites simultaneously. Security researchers have repeatedly flagged network infrastructure management tools as high-value targets in recent years, and Cisco products in particular have been targeted by both cybercriminal groups and state-linked actors given their widespread deployment in government, telecom and enterprise environments.
Cisco has not publicly detailed who is behind the observed exploitation or how widespread the attacks have been, which is typical practice while an incident is still being investigated. The company's advisory includes indicators organizations can use to check whether their own systems show signs of compromise, alongside the software updates themselves.
The disclosure adds to a steady stream of network-infrastructure vulnerabilities disclosed across the industry this year, as security researchers and threat actors alike increasingly focus on the software that underpins enterprise connectivity rather than only targeting end-user devices or public-facing web applications. Security teams are advised to treat network management consoles — VPN concentrators, SD-WAN controllers, firewall managers and similar tools — as high-priority patching targets given how much of an organization's infrastructure typically depends on them.
For IT and security teams running Catalyst SD-WAN Manager, the immediate recommendation from Cisco and independent security researchers is the same: apply the patched release without delay, review upload logs for suspicious activity predating the fix, and treat any management console showing signs of compromise as a potential entry point into the wider network rather than an isolated incident.