York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Third Cisco SD-WAN Zero-Day in Two Weeks (CVE-2026-20262) — Federal Deadline June 29

York Computer

Cisco quietly disclosed another actively exploited vulnerability in Catalyst SD-WAN Manager this week — the third zero-day in the same product line in roughly two weeks. CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Monday and gave federal agencies until June 29 to patch. If your business sits behind a multi-site network managed by an MSP or telecom partner, Cisco SD-WAN Manager is very likely the box steering your traffic — and the attackers know it.

What was disclosed

Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. The bug is a path traversal flaw in the web UI. CVE-2026-20262 is a path traversal flaw in the solution's web user interface that can be exploited by sending a crafted HTTP request to an affected API endpoint of the affected system.

Cisco's own advisory says the vulnerability was found during internal security testing — yet attackers were already using it. The associated security advisory also states that "the vulnerability was found during internal security testing", raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. That gap between "internal find" and "in-the-wild exploitation" is the part that should worry every IT shop running this platform.

Catalyst SD-WAN Manager isn't a niche product. Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) is the management plane for the entire Cisco SD-WAN fabric. If an attacker owns Manager, they own the routing, the policies, and the configurations pushed down to every branch office.

Why this is bigger than one CVE

CVE-2026-20262 is the third Catalyst SD-WAN Manager flaw in a matter of weeks. Since the beginning of this year, Cisco has released fixes for a handful of Catalyst SD-WAN Manager vulnerabilities that attackers have been exploiting as zero- or n-days: The already mentioned CVE-2026-20245 (allowing privilege escalation), CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 (two information disclosure and one arbitrary file overwrite vulnerability, respectively), CVE-2026-20127 (an authentication bypass bug).

That's a sustained, methodical campaign against one product. When a critical management platform takes this many hits in this short a window, the assumption inside any competent MSP should flip from "we'll patch when the change window opens" to "assume the box is being probed right now." Keeping an inventory of every internet-exposed appliance — and a defined patch SLA for each — is exactly the kind of basic discipline covered under York Computer's managed IT services.

CISA's clock is already running

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Monday, and ordered US federal civilian agencies to address it by June 29, 2026. The 14-days-long remediation period is consistent with the requirements laid out in CISA's new Binding Operational Directive, which orders agencies to prioritize security updates based on risk.

The federal deadline doesn't legally bind a small business in York County. But KEV entries are the cleanest public signal we get that a flaw is being actively weaponized. When CISA shortens its own deadlines, private-sector defenders should match the urgency — not wait for the quarterly maintenance window.

What your managed-IT provider should be doing this week

If you outsource networking — and most small businesses do — your provider should already be able to answer four questions in plain English:

1. Do we run any Cisco Catalyst SD-WAN Manager, vManage, or vSmart instances on your network or on our shared infrastructure? If yes, are management interfaces reachable from the public internet? 2. Are CVE-2026-20262, CVE-2026-20245, and CVE-2026-20127 patched on every instance touching your traffic — with a date and a version number, not a "yes"? 3. Have we reviewed admin accounts, SSH keys, and configuration backups for signs of unauthorized changes since May? 4. If a config push from Manager started doing something weird tomorrow, would we notice within minutes or within days?

If the answers are vague, that's the issue. "We'll get to it" is not a patch posture when CISA is measuring response in days.

What York Businesses Should Do

York County businesses running multi-site networks — manufacturers, healthcare practices with satellite offices, school districts — are the most likely local users of Cisco SD-WAN gear, usually through a telecom or MSP. Ask your provider this week for written confirmation that every Catalyst SD-WAN Manager instance in your environment is patched against the three actively exploited CVEs.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles