CVE-2026-20262: Cisco SD-WAN Manager Zero-Day — Path Traversal to Root + CISA KEV
Technical root cause and remediation for the actively exploited Cisco SD-WAN Manager path traversal flaw.
CVE-2026-20262
Severity: CVSS 9.8
Status: ⚠️ Actively Exploited Zero-Day (CISA KEV)
Target Component: Cisco Catalyst SD-WAN Manager
This post is part of the Week of June 19, 2026 Security Roundup.
Vulnerability Overview
CVE-2026-20262 is an arbitrary file-write (path traversal, CWE-22) vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage) — the centralized management interface for Cisco's SD-WAN fabric, capable of controlling up to 6,000 WAN edge devices from a single pane of glass. The flaw stems from insufficient input validation during file upload operations: an authenticated attacker can craft an HTTP request that causes the server to write or overwrite files at arbitrary locations on the underlying filesystem.
- CVE: CVE-2026-20262
- CVSS v3.1: 6.5 (Medium) — AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- CWE: CWE-22 (Path Traversal)
- Vendor advisory: cisco-sa-sdwan-rpa-EHchtZk (June 15–16, 2026)
- CISA KEV: Added June 15, 2026 — federal remediation deadline June 29, 2026
- Status: Patch available; no workarounds
Technical Analysis
The vulnerability exists in the API endpoint responsible for handling file uploads in the SD-WAN Manager web interface. The server-side code fails to normalize the user-supplied filename before constructing the target filesystem path, allowing classic ../ traversal sequences to escape the intended upload directory.
Exploitation chain:
- Attacker authenticates with a low-privilege account (write-access single-task user) — the only prerequisite.
- Crafted HTTP POST to the affected upload API endpoint injects path traversal characters in the filename parameter, directing the write to an attacker-controlled path (e.g., the WildFly application server's
deployments/directory). - Attacker uploads a malicious WAR file containing a JSP web shell.
- WildFly auto-deploys the WAR; attacker calls the JSP via the vManage service proxy to execute arbitrary commands.
- Post-exploitation: privilege escalation to root via the deployed web shell running in the context of the vManage process, which runs as root on default installations.
Scope note: The CVSS score of 6.5 reflects the authentication requirement. However, in many SD-WAN deployments, the manager interface is accessible from the management network with shared or weakly protected credentials, significantly reducing the effective barrier. In real-world exploitation, CISA confirmed "limited, targeted" in-the-wild attacks before the patch was released.
Affected Versions
- Cisco Catalyst SD-WAN Manager all versions prior to 20.12.4, 20.13.3, 20.14.1
- All deployment types: on-prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), Cisco SD-WAN for Government (FedRAMP)
Detection
Cisco's advisory provides concrete detection leads. Inspect the following log files for suspicious activity:
/var/log/nms/vmanage-server.log— look for uploads of.warandindex.jspfiles/var/log/nms/vmanage-appserver.log— look for WAR deployment events/var/log/nms/serviceproxy-access.log— look for requests to the deployed WAR path post-deployment
Indicators of exploitation: unexpected .war files in the WildFly deployments directory; index.jsp accessible through the service proxy; root-level file modifications timestamped during periods with no scheduled maintenance.
Remediation
There are no workarounds. Upgrade to a fixed release immediately:
# Verify current version
show version
# Fixed releases:
# 20.12.4, 20.13.3, 20.14.1 and later
# If immediate upgrade is not possible, restrict SD-WAN Manager access:
# - Isolate the management interface to a dedicated management VLAN
# - Enforce firewall rules permitting access only from trusted admin hosts
# - Enable MFA on all SD-WAN Manager accounts (especially write-access roles)
# - Review all user accounts with write permissions — revoke any that are stale or unnecessary
FCEB agencies must remediate by June 29, 2026 per BOD 22-01.