---
schema: 1
kind: vulnerability
title: "CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV)"
headline: "CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV)"
summary: "Cisco Catalyst SD-WAN Manager actively exploited — CVE-2026-20262 (authenticated arbitrary file write → root RCE) added to the CISA KEV catalog on 2026-06-15; patch to the fixed train and review appserver upload logs. Full deep dive in § 5. (BleepingComputer, 2026-06-15)"
discovered_at: "2026-06-16T05:08:57Z"
event_date: 2026-06-15
run_id: 2026-06-16-38d638e1
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - path-traversal
  - cisa-kev
regions:
  - global
sectors:
  - telco
  - public-sector
entities: []
cves:
  - id: CVE-2026-20262
    cvss: "6.5"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ"
    publisher: Cisco PSIRT advisory
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/"
    publisher: BleepingComputer
    role: corroborating
  - url: "https://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916"
    publisher: The Register
    role: corroborating
closed_sources: []
evidence:
  - quote: "A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) lets an authenticated, remote attacker create or overwrite any file on the underlying OS because the file-upload handler fails to validate the supplied filename (NVD CVSS 6.5; Cisco PSIRT, 2026-06-15)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch Cisco Catalyst SD-WAN Manager now (CVE-2026-20262)** — actively exploited, CISA KEV. Move to a fixed train (20.9.9.2 / 20.12.7.2 / 20.15.4.5 / 20.15.5.3 / 20.18.3.1 / 26.1.1.2), take the management UI off the internet, enforce MFA, and review appserver upload/deploy logs and the Tomcat deploy directory for planted `.jsp`/`.war` web shells."
migrated_from: briefs/2026-06-16.md
---

A path-traversal weakness in the web UI of **Cisco Catalyst SD-WAN Manager** (formerly SD-WAN vManage) lets an authenticated, remote attacker create or overwrite any file on the underlying OS because the file-upload handler fails to validate the supplied filename ([NVD CVSS 6.5](https://nvd.nist.gov/vuln/detail/CVE-2026-20262); [Cisco PSIRT, 2026-06-15](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ)). Writing a JSP/WAR into the Tomcat deploy path yields a web shell and root-level execution, so the modest 6.5 base score understates impact on an exposed network-management plane. Cisco confirms active exploitation and CISA added it to the KEV catalog on 2026-06-15 ([BleepingComputer, 2026-06-15](https://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/)). Patch to 20.9.9.2 / 20.12.7.2 / 20.15.4.5 / 20.15.5.3 / 20.18.3.1 / 26.1.1.2. Full kill-chain, hunt and hardening detail in § 5.
