CVE Tools

Cisco патчит уязвимость нулевого дня в SD-WAN

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedCisco Catalyst SD-WAN ManagerSD-WAN vManage

Our summary

Cisco has released patches for the zero-day vulnerability CVE-2026-20262 in Catalyst SD-WAN Manager (formerly SD-WAN vManage). The issue has been observed in real-world attacks, where it could be leveraged to escalate privileges to root by sending a crafted HTTP request that allowed creation or overwriting of arbitrary files via a vulnerable API. This matters for organizations managing SD-WAN centrally—CISA has added CVE-2026-20262 to its known exploited vulnerabilities catalog and directed federal agencies to remediate by 29 June 2026.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store