Cisco security patch release for CVE-2026-20262
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root privileges. The fixed-build map spans 20.9, 20.12, 20.15, 20.18, and 26.1 trains, and the issue affects on-prem and cloud-managed deployments. Administrators were told to upgrade and review logs for index.jsp and .war upload attempts.
Related Happenings
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
Campaign
H score38
First: 25.06.2026 17:15
Last: 25.06.2026 17:15
Sources 1
About this happening:
An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
CampaignAbout this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch Release
H score56
First: 04.06.2026 14:09
Last: 04.06.2026 14:09
Sources 1
About this happening:
Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch ReleaseAbout this happening: Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco security patch release for CVE-2026-20182
Security Patch Release
H score60
First: 14.05.2026 20:45
Last: 14.05.2026 20:45
Sources 1
About this happening:
Cisco released updates for CVE-2026-20182, a maximum-severity authentication bypass in Catalyst SD-WAN Controller/Manager, after the flaw was exploited in limite...
Cisco security patch release for CVE-2026-20182
Security Patch ReleaseAbout this happening: Cisco released updates for CVE-2026-20182, a maximum-severity authentication bypass in Catalyst SD-WAN Controller/Manager, after the flaw was exploited in limite...
TP-Link security patch release for CVE-2025-15517
Security Patch Release
H score26
First: 25.03.2026 13:11
Last: 25.03.2026 13:11
Sources 1
About this happening:
TP-Link released security updates for its Archer NX router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
TP-Link security patch release for CVE-2025-15517
Security Patch ReleaseAbout this happening: TP-Link released security updates for its Archer NX router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
Timeline
-
15.06.2026 20:12 3 articles · 1mo ago
Cisco releases security updates for CVE-2026-20262 in Catalyst SD-WAN Manager
Mitigation Patch UpdateCisco released security updates for Catalyst SD-WAN Manager, formerly SD-WAN vManage, to address CVE-2026-20262 after attacks exploited the flaw to escalate to root privileges. The issue affects all deployment types, including on-prem deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), and Cisco advised upgrading to the first fixed releases 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2. Cisco also shared IOCs for vmanage-server, vmanage-appserver, and serviceproxy-access logs to detect attempts to upload index.jsp and .war files.
Show sources
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks — www.bleepingcomputer.com — 15.06.2026 20:12
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks — www.bleepingcomputer.com — 15.06.2026 20:12
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw — thehackernews.com — 16.06.2026 09:05