Cisco Security Update – 16 June 2026

Cisco has released a security update to fix a zero-day vulnerability affecting the Cisco Catalyst SD-WAN Manager.

The addressed vulnerability could allow the authenticated remote attacker to create a file or overwrite any file on the filesystem of the affected system.

The addressed vulnerability:

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability (CVE-2026-20262):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: File Manipulation

It should be highlighted that Cisco PSIRT is aware that the zero-day vulnerability “CVE-2026-20262” is being exploited in the wild.

Vulnerabilities

CVE-2026-20262

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Update

References