CVE-2026-20262
CVE-2026-20262: 1 tracked advisory record across Cisco. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-20262] Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
cisco-sa-sdwan-arbfw-c2rZvQSource published Source updated
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least write access. Cisco has released software updates that address this…
- Related products — impact not confirmed
- Catalyst SD-WAN Manager
- Source-reported affected versions
- Scope: At the time of publication, this vulnerability affected Cisco Catalyst SD-WAN Manager, regardless of device configuration.
- Release 20.9.9.1 and earlier (first fixed: 20.9.9.2)
- Release 20.12.7.1 and earlier (first fixed: 20.12.7.2)
- Release 20.15.4.4 and earlier (first fixed: 20.15.4.5)
3 more entries in the full advisory.
- Source-reported fixed versions
- 20.9.9.2
- 20.12.7.2
- 20.15.4.5
- 20.15.5.3
2 more entries in the full advisory.
- Mitigation guidance
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release 20.9.9.1 and earlier: upgrade to 20.9.9.2.
- Release 20.12.7.1 and earlier: upgrade to 20.12.7.2.
- Release 20.15.4.4 and earlier: upgrade to 20.15.4.5.
3 more entries in the full advisory.
- Workarounds
- There are no workarounds that address this vulnerability.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.