Medium Known exploited (KEV) CVE-2026-20262

Path traversal in Cisco Catalyst SD-WAN Manager (CVE-2026-20262) — an authenticated attacker can create or overwrite arbitrary files

Cisco Catalyst SD-WAN Manager Added to KEV Jun 15, 2026 Federal remediation due 2026-06-29

Cisco Catalyst SD-WAN Manager, a network-management product, contains a directory/path traversal flaw (CWE-22). An authenticated, remote attacker can create a file or overwrite any file on the system. The CVSS published on NVD is 6.5 (MEDIUM). CISA added it to the KEV on 2026-06-15, due 2026-06-29.

Key facts

  • CVE IDCVE-2026-20262
  • CVSS base score6.5 MEDIUM
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Affected (vendor / product)Cisco Catalyst SD-WAN Manager
  • CWECWE-22
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-06-29 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Path traversal (CWE-22) in Cisco Catalyst SD-WAN Manager — an authenticated remote attacker can create files or overwrite any file.
  • The CVSS published on NVD is 6.5 (MEDIUM; PR:L, I:H — high impact to integrity).
  • The target is the command post centrally managing SD-WAN (software-defined WAN) — holding the core of communications.
  • File overwriting can be a foothold for seizure or further compromise via config tampering or planting files.
  • CVSS is MEDIUM but it is on the KEV = actually exploited; widely used management products are targets regardless of score.

Path traversal is a flaw in which mixing "../" and the like into a file path reaches files outside the intended range. Here, that is said to let an attacker create files on the affected system or overwrite any file. Overwriting files can, through tampering with configuration files or planting malicious files, become a foothold for seizing the system or for further compromise.

The target, Cisco Catalyst SD-WAN Manager, is the command post that centrally manages an enterprise's SD-WAN (a wide-area network flexibly configured by software). Because network-management products hold the core of communications — settings and routing — writing files to them tends to have wide impact.

The CVSS published on NVD is 6.5 (MEDIUM); the attack requires some privilege (PR:L, i.e. authentication), but the impact to integrity (I:H) is rated high.

The number is MEDIUM, but CISA's addition to the KEV means this flaw is being exploited in real attacks. Regardless of a high or low CVSS, weaknesses in widely used network-management products become real targets — being on the KEV is the proof. The response is prompt updating per Cisco's guidance.

Why it matters

Network-management products hold the core of communications — settings and routing — so creating or overwriting files on them tends to have wide impact. The CVSS is MEDIUM (6.5), but being on the KEV means actual exploitation, showing that widely used management products are targeted regardless of the score. Cisco operators should update per Cisco's guidance and review the management console's exposure.

FAQ

What is path traversal?
A flaw where mixing "../" into a file path reaches files outside the intended range. Here it is said to allow creating files or overwriting any file, which can be a foothold for config tampering or planting malicious files.
Why act if the CVSS is only MEDIUM?
Because CISA added it to the KEV (flaws confirmed exploited in the wild). Even a mid CVSS, weaknesses in widely used network-management products are targeted in reality; being on the KEV means it is being exploited right now.
What should I do?
Update promptly per Cisco's guidance. CISA requires BOD 26-04-based prioritization. Also review whether the management console is exposed externally.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Cisco#Catalyst SD-WAN Manager#CWE-22#Path traversal#Network management#KEV#BOD 26-04
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.