Cisco SD-WAN make-me-root bug under attack
What happened
Cisco released an advisory for a Catalyst SD‑WAN Manager web UI file‑upload flaw (CVE‑2026‑20262) that researchers say has already been exploited to gain root privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and exploitability requires valid credentials for at least a low‑privilege user, so tenant‑level credential hygiene and patching are the immediate operational controls to verify. Watch whether suppliers publish interim mitigations or expanded exploit reports that change the affected surface
Why the category manager should care
Treat this as a real remediation priority for any managed SD‑WAN or orchestration supplier because active exploitation plus a CISA listing shortens acceptable remediation windows
Key facts
- Vulnerability tracked as CVE‑2026‑20262
- Exploit observed in the wild and added to CISA's Known Exploited Vulnerabilities