Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA adds CVE-2026-20262 to KEV and orders federal fixes

Public Sector Action
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixes by June 29, 2026, forcing federal remediation of an actively exploited Cisco SD-WAN flaw. The action targets Cisco Catalyst SD-WAN Manager after evidence showed abuse in the wild. Cisco said the flaw could let an authenticated remote attacker create or overwrite files and potentially reach root. The deadline gives federal agencies a clear remediation window for a live exploitation risk.

Related Happenings

Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign

Campaign
H score38 First: 25.06.2026 17:15 Last: 25.06.2026 17:15 Sources 1

About this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...

Cisco Catalyst SD-WAN Manager actively exploited file upload overwrite flaw (CVE-2026-20262)

Vulnerability
H score24 First: 15.06.2026 20:12 Last: 15.06.2026 20:12 Sources 1

How related: Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.

About this happening: Cisco Catalyst SD-WAN Manager was patched for CVE-2026-20262 after attackers used it to create or overwrite files and escalate to root across all deployment type...

Cisco Catalyst SD-WAN Manager root privilege escalation flaw (CVE-2026-20245)

Vulnerability
H score60 First: 05.06.2026 09:24 Last: 05.06.2026 09:24 Sources 1

About this happening: CVE-2026-20245 in Cisco Catalyst SD-WAN Manager is an actively exploited high-severity vulnerability that can let an authenticated local attacker with netadm...

Latest development: 06.06.2026 07:19

Cisco warned that CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, is under active exploitation and can let an authenticated local attacker with netadmin privileges upload a crafted file to execute arbitrary commands as root. Cisco said the flaw affects On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), that limited exploitation has already resulted in configuration changes pushed to edge devices, and that no patches or mitigations are currently available. Cisco also advised checking /var/log/scripts.log for indicators of compromise and credited Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan with discovering and reporting the issue.

CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182

Public Sector Action
H score59 First: 15.05.2026 08:28 Last: 15.05.2026 08:28 Sources 1

About this happening: CISA added CVE-2026-20182 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to remediate Cisco Catalyst SD-WAN Controller by May 17,...

Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)

Vulnerability
H score60 First: 14.05.2026 23:09 Last: 14.05.2026 23:09 Sources 1

About this happening: CVE-2026-20182 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, creating a path to administr...

Latest development: 14.05.2026 23:25

Cisco released a patch for CVE-2026-20182, giving organizations using Cisco Catalyst SD-WAN Controllers a way to block the authentication bypass before UAT-8616 can continue using it for administrative access, SSH key insertion, NETCONF changes, and root escalation.

Timeline

  1. 16.06.2026 09:05 2 articles · 29d ago

    CISA adds CVE-2026-20262 to KEV and orders federal fixes

    Legal Policy Action Update

    CISA added CVE-2026-20262 in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixes by June 29, 2026 after the flaw was found to be actively exploited in the wild.

    Show sources