โŒ

Normal view

Cisco SD-WAN make-me-root bug under attack

15 June 2026 at 21:48
Cisco today issued a fix for a Catalyst SD-WAN Manager bug that attackers have already spotted and exploited to get root privileges, according to both the networking vendor and the feds. The vulnerability, tracked as CVE-2026-20262, is in the web UI of Cisco Catalyst SD-WAN Manager, and exists because the software is not properly validating user-supplied input during a file upload process. โ€œAn attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system,โ€ the vendor warned in a Monday security advisory. โ€œA successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root.โ€ There is one caveat: to exploit this bug, the attacker must have valid credentials with at least a lower-privileged, single-task user account. That probably explains the medium-severity, 6.8 CVSS rating for this bug. Still, valid credentials arenโ€™t hard to come by these days, and considering this CVE is already under attack, we know someone had some success. โ€œIn June 2026, the Cisco PSIRT became aware of limited exploitation of this vulnerability,โ€ the security alert said. โ€œCisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability.โ€ The flaw affects all deployment types, regardless of device configuration. There are no workarounds, but upgrading to a fixed software version will patch the flaw. Also on Monday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog, citing โ€œevidence of active exploitation.โ€ Americaโ€™s lead cyber-defense agency also set a two-week deadline for all federal agencies to apply the patch. This latest Cisco SD-WAN bug under attack comes less than two weeks after Switchzilla warned that a high-severity vulnerability in Catalyst SD-WAN Manager vulnerability (CVE-2026-20245) was under active exploitation. At the time of disclosure, this SD-WAN vuln did not have a fix. Cisco issued an advisory for that zero-day on June 4, and finally released patches for all affected versions on June 12. This is the eighth Cisco SD-WAN bug to be listed in CISAโ€™s Known Exploited Vulnerabilities catalog so far this year.ยฎ

โŒ