An attacker with a low-privileged account and one crafted HTTP request

That's all it takes to write root-level files onto the platform managing your entire SD-WAN fabric.

CVE-2026-20262 — CVSS 6.5 — arbitrary file write in Cisco Catalyst SD-WAN Manager, actively exploited in the wild. Cisco confirmed exploitation in June. CISA added it to the KEV catalog. There is no workaround — only the patch closes it.

WHAT ACTUALLY HAPPENED

The flaw lives in SD-WAN Manager's web UI file upload handling. Inadequate validation of user input lets an authenticated attacker with write access send a crafted HTTP request to an API endpoint and create or overwrite any file on the underlying OS.

The CVSS score reads moderate. The outcome is not. Arbitrary file write on the box that controls SD-WAN policy and routing across your fabric is a direct path to root. Cisco confirms this can be weaponized for exactly that.

The flaw affects every deployment model — on-premises, Cloud-Pro, Cisco-managed cloud, and FedRAMP alike. No configuration sits outside this exposure.

WHY A MODERATE SCORE STILL MEANS EMERGENCY PATCHING

CVSS 6.5 does not scream urgency on a dashboard sorted by severity. That is the gap attackers exploit. A file-write primitive on a controller with root-adjacent trust turns one valid credential into full compromise of the platform steering every site in your deployment.

If your patch prioritization runs on CVSS score alone, this CVE sails past it while exploitation continues underneath. It isn't isolated — the same weeks saw active exploitation attempts against Fortinet and Palo Alto edge devices too. Attackers are working the entire perimeter, not one vendor.

WHAT TO DO NOW

PATCH IMMEDIATELY — Cisco shipped fixed software for every affected branch. There is no workaround. Upgrading is the only remediation.

AUDIT SD-WAN MANAGER CREDENTIALS — any account with write access is a viable path. Review who holds one and whether they still need it.

CHECK FOR UNEXPECTED FILES — review the filesystem for files created or modified outside your change window, especially anything with elevated execution permissions.

TREAT THE CONTROLLER AS CROWN-JEWEL INFRASTRUCTURE — SD-WAN Manager sees and shapes every site's traffic. A CVSS score is a prioritization input, not a verdict on what an attacker can do with it.

CROSS-CHECK YOUR OTHER EDGE DEVICES — if Cisco is in your environment, Fortinet and Palo Alto likely are too. Confirm patch status across all three before treating this as closed.

The score said moderate. The access it hands over says otherwise.

Do you know which credentials on your SD-WAN Manager still have write access they no longer need?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.