Skip to main content
CISA Known Exploited Vulnerabilities

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2026-06-15
Remediation due
2026-06-29

Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20262

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

Severity

CVSS 3.1 · CNA6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
CiscoCisco Catalyst SD-WAN Manager
20.1.12
19.2.1
18.4.4
18.4.5
20.1.1.1
20.1.1
19.3.0
19.2.2
19.2.099
18.3.6
18.3.7
19.2.0
18.3.8
19.0.0
19.1.0
18.4.302
18.4.303
19.2.097
19.2.098
17.2.10
18.3.6.1
19.0.1a
18.2.0
18.4.3
18.4.1
17.2.8
18.3.3.1
18.4.0
18.3.1
17.2.6
17.2.9
18.3.4
17.2.5
18.3.1.1
18.3.5
18.4.0.1
18.3.3
17.2.7
17.2.4
18.3.0
19.2.3
18.4.501_ES
20.3.1
20.1.2
19.2.929
19.2.31
20.3.2
19.2.32
20.3.2_925
20.3.2.1
20.3.2.1_927
18.4.6
20.1.2_937
20.4.1
20.3.2_928
20.3.2_929
20.4.1.0.1
20.3.2.1_930
19.2.4
20.5.0.1.1
20.4.1.1
20.3.3
19.2.4.0.1
20.3.2_937
20.3.3.1
20.5.1
20.1.3
20.3.3.0.4
20.3.3.1.2
20.3.3.1.1
20.4.1.2
20.3.3.0.2
20.4.1.1.5
20.4.1.0.01
20.4.1.0.02
20.3.3.1.7
20.3.3.1.5
20.5.1.0.1
20.3.3.1.10
20.3.3.0.8
20.4.2
20.4.2.0.1
20.3.4
20.3.3.0.14
19.2.4.0.8
19.2.4.0.9
20.3.4.0.1
20.3.2.0.5
20.6.1
20.5.1.0.2
20.3.3.0.17
20.6.1.1
20.6.0.18.3
20.3.2.0.6
20.6.0.18.4
20.4.2.0.2
20.3.3.0.16
20.3.4.0.5
20.6.1.0.1
20.3.4.0.6
20.6.2
20.7.1EFT2
20.3.4.0.9
20.3.4.0.11
20.4.2.0.4
20.3.3.0.18
20.7.1
20.6.2.1
20.3.4.1
20.5.1.1
20.4.2.1
20.4.2.1.1
20.3.4.1.1
20.3.813
20.3.4.0.19
20.4.2.2.1
20.5.1.2
20.3.4.2
20.3.814
20.4.2.2
20.6.2.2
20.3.4.2.1
20.7.1.1
20.3.4.1.2
20.6.2.2.2
20.3.4.0.20
20.6.2.2.3
20.4.2.2.2
20.3.5
20.6.2.0.4
20.4.2.2.3
20.3.4.0.24
20.6.2.2.7
20.6.3
20.3.4.2.2
20.4.2.2.4
20.7.1.0.2
20.8.1
20.3.5.0.8
20.3.5.0.9
20.4.2.2.8
20.3.5.0.7
20.6.3.0.7
20.6.3.0.5
20.6.3.0.10
20.6.3.0.2
20.7.2
20.9.1EFT2
20.6.3.0.11
20.6.3.1
20.6.3.0.14
20.6.4
20.9.1
20.6.3.0.19
20.6.3.0.18
20.3.6
20.9.1.1
20.6.3.0.23
20.6.4.0.4
20.6.3.0.25
20.6.5
20.6.3.0.27
20.9.2
20.9.2.1
20.6.3.0.29
20.6.3.0.31
20.6.3.0.32
20.10.1
20.6.3.0.33
20.9.2.0.01
20.9.1_LI_Images
20.10.1_LI_Images
20.9.2_LI_Images
20.3.7
20.9.3
20.6.5.1
20.11.1
20.11.1_LI_Images
20.9.3_LI_ Images
20.6.3.1.1
20.9.3.0.2
20.6.5.1.2
20.9.3.0.3
20.4.2.3
20.6.3.2
20.6.4.1
20.6.3.0.38
20.6.3.0.39
20.3.5.1
20.3.4.3
20.9.3.1
20.3.3.2
20.6.5.2
20.3.7.1
20.10.1.1
20.6.5.2.1
20.3.4.0.25
20.6.2.2.4
20.6.1.2
20.11.1.1
20.9.3.0.5
20.3.4.0.26
20.6.5.1.3
20.6.3.0.40
20.1.3.1
20.9.2.2
20.6.5.2.3
20.6.5.1.4
20.6.5.3
20.6.3.0.41
20.9.3.0.7
20.6.5.1.5
20.9.3.0.4
20.6.4.0.19
20.6.5.1.6
20.9.3.0.8
20.6.3.3
20.3.7.2
20.6.5.4
20.6.5.1.7
20.9.3.0.12
20.6.4.2
20.6.5.5
20.9.3.2
20.11.1.2
20.6.3.4
20.10.1.2
20.6.5.1.9
20.9.3.0.16
20.6.3.0.45
20.6.5.1.10
20.9.3.0.17
20.6.5.2.4
20.6.4.0.21
20.9.3.0.18
20.6.3.0.46
20.6.3.0.47
20.9.2.3
20.9.3.2_LI_Images
20.9.3.0.21
20.9.3.0.20
20.9.4_LI_Images
20.9.4
20.6.5.1.11
20.12.1
20.12.1_LI_Images
20.6.5.1.13
20.9.3.0.23
20.6.5.2.8
20.9.4.1
20.9.4.1_LI_Images
20.9.3.0.25
20.9.3.0.24
20.6.5.1.14
20.3.8
20.6.6
20.9.3.0.26
20.6.3.0.51
20.9.3.0.29
20.12.2
20.12.2_LI_Images
20.6.6.0.1
20.13.1_LI_Images
20.9.4.0.4
20.13.1
20.9.4.1.1
20.9.5
20.9.5_LI_Images
20.12.3_LI_Images
20.12.3
20.9.4.1.3
20.6.7
20.9.5.1
20.9.5.1_LI_Images
20.9.4.1.6
20.14.1
20.14.1_LI_Images
20.9.5.2
20.9.5.2.1
20.9.5.2_LI_Images
20.12.3.1
20.12.4
20.15.1_LI_Images
20.15.1
20.9.5.1.4
20.9.5.2.7
20.9.5.2.13
20.9.6
20.9.6_LI_Images
20.9.5.2.14
20.6.8
20.12.4.0.03
20.16.1
20.16.1_LI_Images
20.12.4_LI_Images
20.9.5.2.16
20.12.4.0.4
20.12.401
20.9.5.3
20.9.5.3_LI_Images
20.12.4.1_LI_Images
20.12.4.1
20.9.5.2.21
20.9.6.0.3
20.12.4.0.6
20.15.2_LI_Images
20.15.2
20.12.4_Monthly_ES5
20.12.5
20.12.5_LI_Images
20.9.7_LI _Images
20.9.7
20.15.3
20.15.3_ LI _Images
20.12.501
20.12.5.1_LI_Images
20.12.5.1
20.12.5.2_LI_Images
20.12.5.2
20.15.3.1
20.15.4_LI_Images
20.15.4
20.9.7.1_LI _Images
20.9.7.1
20.18.1
20.18.1_LI_Images
20.12.6_LI_Images
20.12.6
20.12.5.1.01
26.0.1
20.9.8
20.9.8_LI_Images
20.18.2
20.15.4.1_LI_Images
20.15.4.1
20.18.2_LI_Images
26.1.1
26.1.1_LI_Images
20.18.2.1_LI_Images
20.18.2.1
20.15.4.2_LI_Images
20.15.4.2
20.12.6.1
20.12.6.1_LI_Images
20.12.5.3
20.12.5.3_LI_Images
20.9.8.2_LI_Images
20.9.8.2
20.18.3
20.18.3_LI_Images
20.15.5
20.15.5_LI_Images
20.12.7
20.12.7_LI_Images
20.9.9
20.9.9_LI_Images
20.18.2.2
20.18.2.2_LI_Images
20.12.5.4
20.12.5.4_LI_ Images
20.12.7.1_LI_Images
20.12.6.2_LI_Images
20.12.7.1
20.15.5.1
20.15.4.3
20.15.4.3_LI_Images
20.15.5.1_LI_Images
20.12.6.2
20.15.5.2
20.15.5.2_LI_Images
26.1.1.1_LI_Images
20.15.4.4
20.15.4.4_LI_Images
26.1.1.1
20.9.9.1_LI_Images
20.9.9.1

References

1 Links

Record Details

Published
2026-06-15
Last updated
2026-06-17
Assigner (CNA)
cisco
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.