{"id":1323,"date":"2026-06-16T07:06:57","date_gmt":"2026-06-16T07:06:57","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1323"},"modified":"2026-06-16T07:06:57","modified_gmt":"2026-06-16T07:06:57","slug":"cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1323","title":{"rendered":"Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 16, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-vJIadGle0Cre1cNAxZIcD9ktkl1mPnUwtEtF1xuMbeH75BnvGq3twL0W2OowYW7ZZMxvzMjdbU-VMEZfEvV1q2pTIoG8VU_D0d_rpRqwlViZqUyb1WKcL6pM9Nklx_mISZR2BttoBxMq8w6Z87rf3Stm37ZbcRbAYM0SQeEJqg0T8dc2KsrX1a9l95B7\/s1700-e365\/cisco-flaw.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.<\/p>\n<p>The vulnerability, tracked as <b>CVE-2026-20262<\/b>, carries a CVSS score of 6.5 out of 10.0.<\/p>\n<p>\u00abA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system,\u00bb Cisco <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-arbfw-c2rZvQ\">said<\/a> in an advisory.<\/p>\n<p>The issue, the networking equipment company added, stems from inadequate validation of user-supplied input during a file upload process. An attacker could exploit this behavior to create or overwrite any file on the underlying operating system by sending crafted HTTP requests to an affected API endpoint.<\/p>\n<p>This, in turn, could be weaponized to elevate to the root. However, successful exploitation hinges on the attacker already having valid credentials with at least write access.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The vulnerability impacts the following products regardless of the deployment type &#8211;<\/p>\n<ul>\n<li>Cisco Catalyst SD-WAN Manager On-Prem<\/li>\n<li>Cisco SD-WAN Cloud-Pro<\/li>\n<li>Cisco SD-WAN Cloud (Cisco Managed)<\/li>\n<li>Cisco SD-WAN for Government (FedRAMP)<\/li>\n<\/ul>\n<p>Patches have been released to address the issue &#8211;<\/p>\n<ul>\n<li>Cisco Catalyst SD-WAN Release 20.9.9.1 and earlier &#8211; Fixed in 20.9.9.2<\/li>\n<li>Cisco Catalyst SD-WAN Release 20.12.7.1 and earlier &#8211; Fixed in 20.12.7.2<\/li>\n<li>Cisco Catalyst SD-WAN Release 20.15.4.4 and earlier &#8211; Fixed in 20.15.4.5<\/li>\n<li>Cisco Catalyst SD-WAN Release 20.15.5.2 and earlier &#8211; Fixed in 20.15.5.3<\/li>\n<li>Cisco Catalyst SD-WAN Release 20.18.3 &#8211; Fixed in 20.18.3.1<\/li>\n<li>Cisco Catalyst SD-WAN Release 26.1.1.1 and earlier &#8211; Fixed in 26.1.1.2<\/li>\n<\/ul>\n<p>Cisco said it \u00abbecame aware of limited exploitation of this vulnerability\u00bb in June 2026, adding it was discovered during internal security testing.<\/p>\n<p>The company has also shared indicators of compromise associated with the malicious activity, urging customers to audit \u00ab\/var\/log\/nms\/vmanage-server.log\u00bb for suspicious WAR file uploads as below &#8211;<\/p>\n<pre>11-June-2026 03:53:37,310 EDT INFO  [a66cdc5f-807d-4c23-944e-5c809a2ece6b] [server] [SdraAnyConnectFileUploadHandler] (default task-40704) |default| uploaded Remote Access Anyconnect profile file: ..\/..\/..\/..\/var\/lib\/wildfly\/standalone\/deployments\/suspicious.war to vManage.\n<\/pre>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Other indicators include attempts to deploy malicious code and interact with it, although Cisco has warned that they may not \u00abconsistently appear\u00bb in every incident log. The follow-on activities related to this vulnerability are &#8211;<\/p>\n<p>CVE-2026-20262 is the eighth security flaw impacting Cisco SD-WAN to be flagged as actively exploited this year alone after CVE-2026-20245, CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, and CVE-2022-20775. The exploitation of some of these flaws has been attributed to an advanced persistent threat (APT) actor named UAT-8616.<\/p>\n<p>The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/06\/15\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">add<\/a> the flaw to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">KEV<\/a>) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 29, 2026.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 16, 2026Vulnerability \/ Network Security Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1324,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[201,124,128,70,473,1739,125,47,619],"class_list":["post-1323","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actively","tag-cisco","tag-exploited","tag-flaw","tag-manager","tag-releases","tag-sdwan","tag-security","tag-updates"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1323"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1323\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1324"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}