Cisco quietly disclosed another actively exploited vulnerability in Catalyst SD-WAN Manager this week — the third zero-day in the same product line in roughly two weeks. CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Monday and gave federal agencies until June 29 to patch. If your business sits behind a multi-site network managed by an MSP or telecom partner, Cisco SD-WAN Manager is very likely the box steering your traffic — and the attackers know it.
What was disclosed
Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. The bug is a path traversal flaw in the web UI. CVE-2026-20262 is a path traversal flaw in the solution's web user interface that can be exploited by sending a crafted HTTP request to an affected API endpoint of the affected system.
Cisco's own advisory says the vulnerability was found during internal security testing — yet attackers were already using it. The associated security advisory also states that "the vulnerability was found during internal security testing", raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. That gap between "internal find" and "in-the-wild exploitation" is the part that should worry every IT shop running this platform.
Catalyst SD-WAN Manager isn't a niche product. Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) is the management plane for the entire Cisco SD-WAN fabric. If an attacker owns Manager, they own the routing, the policies, and the configurations pushed down to every branch office.
Why this is bigger than one CVE
CVE-2026-20262 is the third Catalyst SD-WAN Manager flaw in a matter of weeks. Since the beginning of this year, Cisco has released fixes for a handful of Catalyst SD-WAN Manager vulnerabilities that attackers have been exploiting as zero- or n-days: The already mentioned CVE-2026-20245 (allowing privilege escalation), CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 (two information disclosure and one arbitrary file overwrite vulnerability, respectively), CVE-2026-20127 (an authentication bypass bug).
That's a sustained, methodical campaign against one product. When a critical management platform takes this many hits in this short a window, the assumption inside any competent MSP should flip from "we'll patch when the change window opens" to "assume the box is being probed right now." Keeping an inventory of every internet-exposed appliance — and a defined patch SLA for each — is exactly the kind of basic discipline covered under York Computer's managed IT services.
CISA's clock is already running
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20262 to its Known Exploited Vulnerabilities catalog on Monday, and ordered US federal civilian agencies to address it by June 29, 2026. The 14-days-long remediation period is consistent with the requirements laid out in CISA's new Binding Operational Directive, which orders agencies to prioritize security updates based on risk.
The federal deadline doesn't legally bind a small business in York County. But KEV entries are the cleanest public signal we get that a flaw is being actively weaponized. When CISA shortens its own deadlines, private-sector defenders should match the urgency — not wait for the quarterly maintenance window.
What your managed-IT provider should be doing this week
If you outsource networking — and most small businesses do — your provider should already be able to answer four questions in plain English:
1. Do we run any Cisco Catalyst SD-WAN Manager, vManage, or vSmart instances on your network or on our shared infrastructure? If yes, are management interfaces reachable from the public internet? 2. Are CVE-2026-20262, CVE-2026-20245, and CVE-2026-20127 patched on every instance touching your traffic — with a date and a version number, not a "yes"? 3. Have we reviewed admin accounts, SSH keys, and configuration backups for signs of unauthorized changes since May? 4. If a config push from Manager started doing something weird tomorrow, would we notice within minutes or within days?
If the answers are vague, that's the issue. "We'll get to it" is not a patch posture when CISA is measuring response in days.
What York Businesses Should Do
York County businesses running multi-site networks — manufacturers, healthcare practices with satellite offices, school districts — are the most likely local users of Cisco SD-WAN gear, usually through a telecom or MSP. Ask your provider this week for written confirmation that every Catalyst SD-WAN Manager instance in your environment is patched against the three actively exploited CVEs.