Cisco SD-WAN Manager Path Traversal Vulnerability: Critical Patch Still Being Exploited
A critical vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-20262) remains actively exploited in the wild, even weeks past the CISA enforcement deadline. If your organization uses this product for network management, you need to take action now. The vulnerability allows authenticated attackers to create or overwrite files on your system—which sounds technical until you realize that means someone with access could plant malware, steal configurations, or disable your network entirely. CISA added this to their Known Exploited Vulnerabilities catalog on June 15, 2026, and the enforcement deadline of June 29 has already passed. That's not a warning about the future; it's a wake-up call about the present.
What This Vulnerability Actually Means for Your Business
Path traversal vulnerabilities are straightforward in concept but dangerous in practice. An authenticated user—someone already inside your system or with legitimate credentials—can navigate the filesystem like they own it. They can write files to locations they shouldn't touch, overwrite critical files, or plant backdoors. In the case of SD-WAN Manager, this is your network brain. If someone compromises it, they don't just break one system; they compromise visibility and control across your entire WAN infrastructure.
The catch that keeps many small business owners up at night: you might not know if you're vulnerable or if someone's already exploited this. Detection and ownership are the real problems here. Many organizations patch sporadically, inherit systems they don't fully understand, or run versions they've forgotten about. That's the gap where active exploits live.
Three Actions to Take This Week
Step 1: Inventory Your Cisco SD-WAN Manager Deployment
Find out if you're actually running Cisco Catalyst SD-WAN Manager, what version you're on, and where it sits in your network. If you use a managed service provider or cloud integrator for this, contact them today and ask directly whether they've patched. Don't assume it's been handled. Document which systems depend on it and whether they're internet-facing. This isn't optional reconnaissance—it's the foundation of everything that follows.
Step 2: Apply Patches or Implement Mitigations Immediately
Cisco has released patches for affected versions. Download them, test them in a non-production environment first if possible, then deploy them. Follow the vendor's instructions exactly. If patches aren't available for your version, apply whatever mitigations Cisco recommends. If neither patches nor mitigations exist, you face a harder choice: upgrade to a supported version or stop using the product. CISA's BOD 26-04 guidance requires you to make this decision formally, not informally.
Step 3: Log, Monitor, and Report
After patching, review your access logs for suspicious activity from authenticated users. Look for file creation or modification events in unexpected directories. If you spot anything suspicious, document it and report it to your security team or incident response provider. Many small businesses skip this step and wonder months later how a breach happened. The evidence is usually there if you look.
Why This Matters More Than the CVE Number
The real issue isn't the vulnerability itself—it's that you might own a Cisco SD-WAN Manager instance you inherited, didn't fully inventory, and haven't patched because nobody told you to. These gaps between what you're running and what you know you're running are where exploits take root. The enforcement deadline passed six weeks ago. If you haven't patched yet, you're operating in violation of CISA's prioritized patching guidance and exposing your network to active attackers.
Defend Your Systems Properly
Patching is necessary but not sufficient. You also need visibility into what's running on your network, strong credential management, and the ability to detect when someone's moving files around where they shouldn't be. That's where dedicated security tools come in. Malwarebytes helps detect malware and suspicious behavior across your endpoints and network. LastPass ensures credentials aren't shared casually or written down—something crucial when multiple people manage critical infrastructure.
For your security team, building expertise in vulnerability management and patch prioritization is non-negotiable. Pluralsight's free trial for individuals includes courses on vulnerability management and secure network architecture. If you're managing a security team, Pluralsight for Teams offers structured learning paths designed for security leads.
Want to defend against this? Train your skills on Pluralsight and build the knowledge to manage these incidents yourself.