Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse
CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

Cisco has shipped fixes for a flaw in Catalyst SD-WAN Manager — the product formerly known as vManage — that the vendor says is already being exploited.
The bug is tracked as CVE-2026-20262 and carries a CVSS score of 6.5. Medium on paper. Less reassuring once you read the description.
The flaw sits in the appliance's web UI. An authenticated remote attacker can abuse it to create files on the underlying system, according to Cisco's advisory. File-write primitives on a management plane device tend to become full compromise primitives in short order, and Catalyst SD-WAN Manager is the orchestration brain for an entire SD-WAN fabric. Anyone with hands on that box can reach the edges.
Cisco has acknowledged exploitation activity. The vendor has not, at time of writing, published indicators of compromise, named a threat cluster, or described the access vector beyond the authentication requirement. That last detail matters. Authenticated-only bugs in management platforms are routinely paired with credential theft, phishing of operator accounts, or a second unpatched flaw to reach the login prompt. Capability is not intent, and authentication is not a moat.
Historically, SD-WAN Manager has been a target of interest for both criminal and state-aligned operators. Earlier vManage vulnerabilities surfaced in advisories from CISA and have shown up in tooling associated with China-nexus intrusion sets in vendor reporting, though no public attribution has been made for this specific CVE. Treat any claims otherwise with skepticism until corroborating telemetry lands.
What to do now:
- Apply Cisco's patched release for Catalyst SD-WAN Manager as soon as your change window allows. The fixed versions are listed in the Cisco Security Advisory.
- Restrict web UI access to a management VLAN or jump host. Public exposure of this interface is the recurring pattern in past SD-WAN Manager incidents.
- Audit local and federated accounts on the appliance. Rotate credentials for any operator account with weak MFA posture.
- Review file system and audit logs for unexpected writes, new cron entries, or unfamiliar service accounts dating back several weeks. Cisco has not committed to a known earliest exploitation date.
The broader pattern is familiar. Edge and management appliances continue to absorb a disproportionate share of in-the-wild exploitation, partly because they sit at trust boundaries and partly because they are difficult to instrument with EDR. Defenders running Catalyst SD-WAN Manager should assume the window between disclosure and broader opportunistic scanning is short.
Medium confidence the patch is the easy part. Verifying you weren't already touched is the work.



