The SD-WAN Control Plane Was Exploited. Cisco Said Preserve Evidence Before Patching.
Cisco told Catalyst SD-WAN customers to preserve evidence before changing the systems they needed to patch. Two exploited vulnerabilities reached the control plane, and one produced limited cases where an unauthorised configuration change was pushed onward to edge devices.
The June advisories cover CVE-2026-20245, a privilege-escalation flaw in SD-WAN control components, and CVE-2026-20262, an arbitrary file-write flaw in SD-WAN Manager. Cisco confirmed exploitation of both vulnerabilities.
Neither flaw is an unauthenticated entry point on its own. The first requires netadmin privileges. The second requires an authenticated account with file-write access. Cisco says the known unauthenticated paths to those credentials are earlier SD-WAN vulnerabilities CVE-2026-20182 and CVE-2026-20127, or possession of valid credentials.
One flaw turned netadmin into root
CVE-2026-20245 affects Catalyst SD-WAN Controller, Manager and Validator, formerly known as vSmart, vManage and vBond. A netadmin user can upload a crafted file that reaches a command-injection path and elevates the attacker to root.
Cisco rates the vulnerability 7.8. It affects on-premises, Cloud-Pro, Cisco-managed cloud and government FedRAMP deployments regardless of device configuration.
The exploitation boundary did not always stop at the compromised controller. Cisco observed limited cases where the attacker caused a configuration change to be pushed to SD-WAN edge devices. Customers therefore need to verify edge configuration as well as patch the control components.
The second flaw could overwrite any file on the Manager
CVE-2026-20262 is a 6.5-rated path-traversal weakness in the SD-WAN Manager web interface. Insufficient validation during file upload lets an authenticated remote attacker create or overwrite any file on the Manager’s filesystem.
The numeric score is medium because the attacker needs an account and the published direct impact is integrity. That score does not describe the surrounding attack chain. Credentials obtained through an earlier authentication bypass can convert a lower-privileged file-write primitive into persistence or a later route to root.
Cisco describes exploitation of this vulnerability as limited. It does not directly affect edge-device filesystems, but it compromises the system that manages the overlay.
Collect admin-tech before the upgrade
Cisco’s remediation workflow begins with evidence preservation. Customers should collect admin-tech files from every Controller, Manager and Validator before upgrading or making configuration changes. The components should be collected one at a time, with Log and Tech selected.
That order matters because an upgrade can rotate, overwrite or remove evidence needed to determine whether the environment was already compromised. Cisco asks customers to open a TAC case and upload the bundles for indicator review. Matching log entries can also occur during legitimate operations, so they need contextual analysis rather than automatic classification.
An update closes the vulnerable path. It does not undo a malicious configuration, remove an attacker-created file or prove that credentials remain trustworthy.
Fixed releases and immediate actions
For both advisories, the fixed trains include 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2. Cisco later added a Live Protect shield for CVE-2026-20245, but calls it temporary partial protection. There are no complete workarounds.
- Preserve admin-tech bundles and relevant logs from all control components before upgrade.
- Upgrade every affected component to the fixed release for its train.
- Verify that prior fixes for CVE-2026-20182 and CVE-2026-20127 are also present.
- Audit recent edge-device configuration changes and compare them with approved change records.
- Rotate administrative credentials and review account creation, SSH keys and unexpected root activity when compromise is suspected.
- Engage incident response if Cisco TAC identifies credible indicators. TAC log review is not a complete forensic investigation.
The operational message is larger than two CVEs. A controller compromise changes what administrators can trust about the network below it. Preserve evidence first, patch the control plane, and then prove that the configuration it distributed is still yours.
Update, 1 September 2026: the earlier SD-WAN bulletin exposed three more control-plane paths
The exploited June chain sits on top of an earlier Cisco SD-WAN advisory that contained three additional vulnerabilities. CISA added all three to its Known Exploited Vulnerabilities catalogue on 20 April.
- CVE-2026-20122 abuses file handling in a privileged API. A malicious upload can overwrite arbitrary files and give the attacker vmanage-user privileges.
- CVE-2026-20128 exposes a recoverable DCA credential to a low-privileged local user, enabling elevation to the DCA account.
- CVE-2026-20133 can expose sensitive information to a remote attacker.
These are separate from CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262 discussed above, but they affect the same management plane. Review Cisco’s release matrix, preserve logs and configuration evidence before remediation, and verify that no unauthorised policy or credential changes reached managed edge devices.
Primary sources: Cisco SD-WAN security advisory and the CISA KEV catalogue.
Sources: Cisco advisory for CVE-2026-20245 (first published 4 June 2026 at 22:27 GMT; updated 21 July 2026 at 16:01 GMT), Cisco advisory for CVE-2026-20262 (first published 15 June 2026 at 16:00 GMT; updated 15 June 2026 at 22:00 GMT), Cisco remediation workflow (first published 5 June 2026 and revised through 1 July 2026; source provides dates but not publication times), and CERT-FR advisory (published 16 June 2026; no publication time provided).


