Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Infinite Campus Data Breach Exposes 137, Users Personal
June 16, 2026
OptinMonster Hack Exposes 1.2M WordPress Plugin Million
June 16, 2026
Hackers Abuse RMM Tools in The Quarry IRS/SSA Legitimate Phishing
June 16, 2026
Home/Vulnerabilities/Cisco SD-WAN vManage Zero-Day Vulner Vulnerability Exploited
Vulnerabilities

Cisco SD-WAN vManage Zero-Day Vulner Vulnerability Exploited

Cisco has disclosed a critical security vulnerability in its Catalyst SD-WAN Manager (formerly vManage) that is now actively exploited in zero-day attacks. This revelation raises significant concern...

Sarah simpson
Sarah simpson
June 16, 2026 2 Min Read
3 0

Cisco has disclosed a critical security vulnerability in its Catalyst SD-WAN Manager (formerly vManage) that is now actively exploited in zero-day attacks. This revelation raises significant concern for enterprise network environments worldwide.

The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a CVSS score of 6.5 and stems from improper validation of user-supplied input during file upload operations.

According to Cisco, attackers with valid credentials and write-level access can exploit this flaw to upload crafted files to targeted systems. Once exploited, the vulnerability allows an attacker to create or overwrite files anywhere on the underlying operating system.

Cisco SD-WAN vManage Vulnerability

This capability can be leveraged to deploy malicious payloads, including web shells, and potentially escalate privileges to root level, significantly increasing the severity of the attack.

Cisco’s Product Security Incident Response Team (PSIRT) confirmed that the vulnerability has already been observed in limited real-world exploitation as of June 2026.

This places the flaw in the category of zero-day vulnerabilities, where attackers can exploit it before widespread patching occurs.

The issue affects all deployment models of Cisco Catalyst SD-WAN Manager, including on-premises systems, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP environments.

Notably, there are no available workarounds, making immediate patching the only effective mitigation. Security researchers highlight that internet-exposed SD-WAN management interfaces are the most at risk.

Attackers can exploit exposed API endpoints by crafting HTTP requests to upload malicious files. One example includes uploading a WAR file to sensitive directories using directory traversal techniques. Cisco has provided specific Indicators of Compromise (IOCs) to help organizations detect potential exploitation.

Suspicious activity may appear in log files such as:

  • vmanage-server.log showing unauthorized file uploads, including paths like “../../../../var/lib/wildfly/standalone/deployments/suspicious.war”.
  • vmanage-appserver.log indicating deployment of unexpected WAR files.
  • serviceproxy-access.log captures HTTP POST requests to malicious endpoints such as “/suspicious/index.jsp”.

These logs suggest post-exploitation activity, where attackers deploy and interact with malicious applications within the system.

Cisco clarified that this vulnerability does not directly affect SD-WAN traffic handling or connectivity.

However, compromise of the management plane could allow attackers to manipulate configurations or maintain persistent access. To address the issue, Cisco has released patched versions across multiple software branches.

Affected users are strongly advised to upgrade to fixed releases such as 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2, depending on their deployment.

Organizations are also encouraged to audit logs, restrict external access to management interfaces, and use the “request admin-tech” command to collect diagnostic data before engaging Cisco TAC for incident response support.

This vulnerability was identified during internal security testing. However, its rapid transition to active exploitation highlights the ongoing risk posed by exposed management interfaces and insufficient input validation mechanisms.

With no workaround available and active attacks underway, timely patching and continuous monitoring remain critical to reducing exposure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers

Next Post

Critical LiteSpeed cPanel 0-Day Actively Plugin Vulnerability

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical LiteSpeed cPanel 0-Day Actively Plugin Vulnerability
June 16, 2026
Cisco SD-WAN vManage Zero-Day Vulner Vulnerability Exploited
June 16, 2026
Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers
June 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us