Cisco SD-WAN Manager Path Traversal Vulnerability: Critical Patch Still Being Exploited

Share

A critical vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-20262) remains actively exploited in the wild, even weeks past the CISA enforcement deadline. If your organization uses this product for network management, you need to take action now. The vulnerability allows authenticated attackers to create or overwrite files on your system—which sounds technical until you realize that means someone with access could plant malware, steal configurations, or disable your network entirely. CISA added this to their Known Exploited Vulnerabilities catalog on June 15, 2026, and the enforcement deadline of June 29 has already passed. That's not a warning about the future; it's a wake-up call about the present.

What This Vulnerability Actually Means for Your Business

Path traversal vulnerabilities are straightforward in concept but dangerous in practice. An authenticated user—someone already inside your system or with legitimate credentials—can navigate the filesystem like they own it. They can write files to locations they shouldn't touch, overwrite critical files, or plant backdoors. In the case of SD-WAN Manager, this is your network brain. If someone compromises it, they don't just break one system; they compromise visibility and control across your entire WAN infrastructure.

The catch that keeps many small business owners up at night: you might not know if you're vulnerable or if someone's already exploited this. Detection and ownership are the real problems here. Many organizations patch sporadically, inherit systems they don't fully understand, or run versions they've forgotten about. That's the gap where active exploits live.

Three Actions to Take This Week

Step 1: Inventory Your Cisco SD-WAN Manager Deployment

Find out if you're actually running Cisco Catalyst SD-WAN Manager, what version you're on, and where it sits in your network. If you use a managed service provider or cloud integrator for this, contact them today and ask directly whether they've patched. Don't assume it's been handled. Document which systems depend on it and whether they're internet-facing. This isn't optional reconnaissance—it's the foundation of everything that follows.

Step 2: Apply Patches or Implement Mitigations Immediately

Cisco has released patches for affected versions. Download them, test them in a non-production environment first if possible, then deploy them. Follow the vendor's instructions exactly. If patches aren't available for your version, apply whatever mitigations Cisco recommends. If neither patches nor mitigations exist, you face a harder choice: upgrade to a supported version or stop using the product. CISA's BOD 26-04 guidance requires you to make this decision formally, not informally.

Step 3: Log, Monitor, and Report

After patching, review your access logs for suspicious activity from authenticated users. Look for file creation or modification events in unexpected directories. If you spot anything suspicious, document it and report it to your security team or incident response provider. Many small businesses skip this step and wonder months later how a breach happened. The evidence is usually there if you look.

Why This Matters More Than the CVE Number

The real issue isn't the vulnerability itself—it's that you might own a Cisco SD-WAN Manager instance you inherited, didn't fully inventory, and haven't patched because nobody told you to. These gaps between what you're running and what you know you're running are where exploits take root. The enforcement deadline passed six weeks ago. If you haven't patched yet, you're operating in violation of CISA's prioritized patching guidance and exposing your network to active attackers.

Defend Your Systems Properly

Patching is necessary but not sufficient. You also need visibility into what's running on your network, strong credential management, and the ability to detect when someone's moving files around where they shouldn't be. That's where dedicated security tools come in. Malwarebytes helps detect malware and suspicious behavior across your endpoints and network. LastPass ensures credentials aren't shared casually or written down—something crucial when multiple people manage critical infrastructure.

For your security team, building expertise in vulnerability management and patch prioritization is non-negotiable. Pluralsight's free trial for individuals includes courses on vulnerability management and secure network architecture. If you're managing a security team, Pluralsight for Teams offers structured learning paths designed for security leads.

Want to defend against this? Train your skills on Pluralsight and build the knowledge to manage these incidents yourself.

Sources

Read more

Federal Contract Alert: Next Generation Ammunition & Munitions Equipment (NGAME) for MMHE RFP/Solicitation — DEPT OF DEFENSE.DEPT OF THE AIR FORCE.AIR FORCE MAT

NGAME MMHE RFP: What This Opportunity Actually Is The Air Force Life Cycle Management Center (AFLCMC) is seeking Next Generation Ammunition & Munitions Handling Equipment (NGAME) for Munitions Maintenance & Handling Equipment (MMHE). This is a production and/or engineering contract aimed at modernizing how the Air Force stores, transports,

By abdul wahib

Federal Contract Alert: J--Landing craft rehabilitation, Lake Roosevelt NRA. — INTERIOR, DEPARTMENT OF THE.NATIONAL PARK SERVICE.PWR OLYM MABO(83000)

What You're Looking At: Landing Craft Rehab at Lake Roosevelt The National Park Service (Power, Olympics & Mountaineer Area Office) is seeking a contractor to rehabilitate landing craft operated at Lake Roosevelt National Recreation Area in Washington State. This is straightforward marine vessel maintenance and repair work—hull

By abdul wahib