LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 15, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 29, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Jun 15, 2026, with a federal patch deadline of Jun 29, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an…

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that permits an authenticated remote attacker to create or overwrite arbitrary files on the affected system. The flaw is tracked as CVE-2026-20262 and is classified under CWE-22. Because the product manages wide-area network infrastructure, successful abuse can alter configuration, binaries, or logs that control traffic routing and device behavior.

How it works

CWE-22 path traversal occurs when user-supplied input is used to construct filesystem paths without sufficient validation or canonicalization. An attacker who already possesses valid credentials can supply sequences such as dot-dot-slash or absolute paths that cause the application to reference locations outside the intended directory. The result is the ability to create new files or replace existing ones anywhere on the filesystem that the process can reach.

The vulnerability does not require unauthenticated network access; the attacker must first authenticate to the SD-WAN Manager interface. No further exploit mechanics are documented in the available summary.

Am I affected? How to find it in your systems

Inventory all deployments of Cisco Catalyst SD-WAN Manager. This software typically runs as a centralized management plane for SD-WAN fabrics and may be deployed on-premises or in cloud-hosted instances. Examine configuration management databases, asset inventories, and network diagrams for instances that expose the management interface.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, verify that the management plane is running the corrected code and that prior credentials have been rotated.

If you can't patch immediately

Follow the mitigations prescribed by the vendor and ensure compliance with CISA BOD 26-04 guidance on prioritizing security updates. Segment the SD-WAN Manager host so that it is reachable only from trusted management networks. Where technically feasible, disable or tightly control any features that accept user-controlled path input until the update can be applied. Increase logging verbosity on authentication and file-write events and forward those logs to a central collector for review. If compensating controls cannot be implemented, evaluate whether continued use of the product meets organizational risk tolerance and regulatory requirements.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to unauthorized changes that facilitate further compromise. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Manager
WeaknessCWE-22
Added to CISA KEVJun 15, 2026
Federal patch deadlineJun 29, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities