Cisco has released security updates to address a vulnerability in its Catalyst SD-WAN Manager (formerly SD-WAN vManage), identified as CVE-2026-20262. Multiple outlets report that the flaw is being actively exploited in the wild, including in attacks that target the product’s web UI and can lead to privilege escalation, including root-level access. SecurityWeek and other sources describe the underlying issue as a zero-day that enables arbitrary file write, which can be used by attackers to gain more control of affected systems.
Cisco’s disclosure also indicates that its Product Security Incident Response Team observed exploitation attempts. In the company’s advisory, Cisco notes that the vulnerability was identified during internal security testing, which has prompted questions about how attackers were able to exploit it before the public disclosure. The reported severity is medium, with one outlet citing a CVSS score of 6.5.
This is described as a second exploited SD-WAN-related issue disclosed by Cisco within a short period, and the updates are intended to mitigate the risk from ongoing attacks against vulnerable Catalyst SD-WAN Manager deployments.