CVE-2026-20262
Coverage of CVE-2026-20262 in the Nexus archive.
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates to address a medium-severity vulnerability (CVE-2026-20262) in its Catalyst SD-WAN Manager, which is being actively exploited. The flaw allows an authenticated remote attacker to create files via the web UI, with a CVSS score of 6.5.
- Cisco SD-WAN make-me-root bug under attack
Cisco issued a fix for a critical vulnerability (CVE-2026-20262) in its Catalyst SD-WAN Manager, which attackers are actively exploiting to gain root privileges. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch within two weeks. The vulnerability arises from improper input validation during file uploads, requiring valid credentials for exploitation.