{"id":13640,"date":"2026-06-16T10:03:35","date_gmt":"2026-06-16T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/16\/cisco-sd-wan-vmanage-vulnerability-exploited-in-zero-day-attacks\/"},"modified":"2026-06-16T10:03:35","modified_gmt":"2026-06-16T10:03:35","slug":"cisco-sd-wan-vmanage-vulnerability-exploited-in-zero-day-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/16\/cisco-sd-wan-vmanage-vulnerability-exploited-in-zero-day-attacks\/","title":{"rendered":"Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks"},"content":{"rendered":"<p>    Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively <a href=\"https:\/\/cybersecuritynews.com\/cisco-catalyst-sd-wan-controller-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">exploited in zero-day attacks<\/a>, raising concerns for enterprise network environments worldwide.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a CVSS score of 6.5 and stems from improper validation of user-supplied input during file upload operations.<\/p>\n<p class=\"wp-block-paragraph\">According to Cisco, attackers with valid credentials and write-level access can exploit this flaw to upload crafted files to targeted systems. Once exploited, the vulnerability allows an attacker to create or overwrite files anywhere on the underlying operating system.<\/p>\n<h2 id=\"h-cisco-sd-wan-vmanage-vulnerability\" class=\"wp-block-heading\"><strong>Cisco SD-WAN vManage Vulnerability<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">This capability can be leveraged to deploy malicious payloads, including web shells, and potentially <a href=\"https:\/\/cybersecuritynews.com\/cisco-sd-wan-vulnerability-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">escalate privileges to root level<\/a>, significantly increasing the severity of the attack.<\/p>\n<p class=\"wp-block-paragraph\">Cisco\u2019s Product Security Incident Response Team (PSIRT) confirmed that the vulnerability has already been observed in limited real-world exploitation as of June 2026.<\/p>\n<p class=\"wp-block-paragraph\">This places the flaw in the category of<a href=\"https:\/\/cybersecuritynews.com\/cisco-sd-wan-manager-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\"> zero-day vulnerabilities<\/a>, where attackers can exploit it before widespread patching occurs.<\/p>\n<p class=\"wp-block-paragraph\">The issue affects all deployment models of Cisco Catalyst SD-WAN Manager, including on-premises systems, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP environments.<\/p>\n<p class=\"wp-block-paragraph\">Notably, there are no available workarounds, making immediate patching the only effective mitigation. Security researchers highlight that internet-exposed SD-WAN management interfaces are the most at risk.<\/p>\n<p class=\"wp-block-paragraph\">Attackers can exploit exposed API endpoints by crafting HTTP requests to upload malicious files. One example includes uploading a WAR file to sensitive directories using directory traversal techniques. Cisco has provided specific Indicators of Compromise (IOCs) to help organizations detect potential exploitation.<\/p>\n<p class=\"wp-block-paragraph\">Suspicious activity may appear in log files such as:<\/p>\n<ul class=\"wp-block-list\">\n<li>vmanage-server.log showing unauthorized file uploads, including paths like \u201c..\/..\/..\/..\/var\/lib\/wildfly\/standalone\/deployments\/suspicious.war\u201d.\n<\/li>\n<li>vmanage-appserver.log indicating deployment of unexpected WAR files.\n<\/li>\n<li>serviceproxy-access.log captures HTTP POST requests to malicious endpoints such as \u201c\/suspicious\/index.jsp\u201d.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">These logs suggest post-exploitation activity, where attackers deploy and interact with malicious applications within the system.<\/p>\n<p class=\"wp-block-paragraph\">Cisco clarified that this vulnerability does not directly affect SD-WAN traffic handling or connectivity.<\/p>\n<p class=\"wp-block-paragraph\">However, compromise of the management plane could allow attackers to manipulate configurations or maintain persistent access. To address the issue, <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-arbfw-c2rZvQ\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cisco has released patched versions<\/a> across multiple software branches.<\/p>\n<p class=\"wp-block-paragraph\">Affected users are strongly advised to upgrade to fixed releases such as 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2, depending on their deployment.<\/p>\n<p class=\"wp-block-paragraph\">Organizations are also encouraged to audit logs, restrict external access to management interfaces, and use the \u201crequest admin-tech\u201d command to collect diagnostic data before engaging Cisco TAC for incident response support.<\/p>\n<p class=\"wp-block-paragraph\">This vulnerability was identified during internal security testing. However, its rapid transition to active exploitation highlights the ongoing risk posed by exposed management interfaces and insufficient input validation mechanisms.<\/p>\n<p class=\"wp-block-paragraph\">With no workaround available and active attacks underway, timely patching and continuous monitoring remain critical to reducing exposure.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-sd-wan-vmanage-vulnerability-exploit\/\">Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-sd-wan-vmanage-vulnerability-exploit\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise network environments worldwide. The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1439,129,63,131],"tags":[130],"class_list":["post-13640","post","type-post","status-publish","format-standard","hentry","category-cisco","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13640"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13640"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13640\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}