INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Exploited

| 2026-06-16 10:53 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat actor is highly targeted, with limited exploitation of the vulnerability in recent attacks. The Cisco Catalyst SD-WAN issue has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), requiring affected systems to be upgraded to a patched software version by June 29, 2026.
Technical Mitigations AI-generated
* Implement input validation and sanitization for user-supplied data, particularly when it comes to file uploads, to prevent arbitrary file writes. * Regularly update and patch operating systems, network devices, and software applications to ensure they have the latest security fixes and patches. * Use secure protocols (e.g., HTTPS) for remote access and communication with affected systems to prevent unauthorized access or data exfiltration. * Limit privileges and access rights of users and services running on affected systems to prevent further compromise or escalation of vulnerabilities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sc•••••.log
su•••••.war
vm•••••.log
in•••••.jsp
ma•••••.csv
vc•••••.sh
20.9.•••.•••
20.12.•••.•••
20.9.•••.•••
20.12.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20245CVE-2026-20245 CVE-2026-20128CVE-2026-20128 CVE-2026-20127CVE-2026-20127 CVE-2026-20133CVE-2026-20133 CVE-2026-20182CVE-2026-20182 CVE-2022-20775CVE-2022-20775 CVE-2026-20262CVE-2026-20262 CVE-2026-20122CVE-2026-20122
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026/05/06
Threat actors exploited a recently disclosed Cisco SD-WAN zero-day vulnerability in the Catalyst SD-WAN Controller.
vulnerability CVE-2026-20182
organisation Catalyst SD-WAN Controller
‎May 14
Threat actors exploited a zero-day vulnerability in Cisco's SD-WAN software, targeting systems with the CVE-2026-20182 patch.
organisation CVE-2026-20245
vulnerability CVE-2026-20182
‎2026/05/16
Threat actors exploited a maximum-severity CVE-2026-20182 zero-day flaw in Cisco Catalyst SD-WAN Controllers to gain admin privileges on unpatched devices.
vulnerability CVE-2026-20182
organisation Catalyst SD-WAN Controller
‎2026/06/09
Threat actors exploited a Cisco Catalyst SD-WAN zero-day vulnerability, CVE-2026-20245.
vulnerability CVE-2026-20245
organisation CVSS
organisation Known Exploited
tactic T1588.006 - Vulnerabilities
organisation KEV
‎Jun 16, 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco's SD-WAN software to target organizations.
‎2026/06/16
A successful attack could enable further privilege escalation to root.
organisation VulnCheck
organisation CVE-2026-20245
organisation SD-WAN vManage
organisation the Cisco Catalyst SD-WAN
organisation CVE-2026
organisation Catalyst SD-WAN
organisation CVE-2026-20262
organisation Cisco Catalyst SD-WAN
organisation CVSS
organisation Cisco SD-WAN
organisation CVE-2022
organisation Product Security Incident Response Team
organisation Vulnerability / Network Security
infrastructure 6,000 WAN devices
organisation UI
organisation Cisco
organisation Cisco SD-WAN Cloud-Pro
organisation the Cisco TAC
organisation Cisco SD-WANs
organisation SD-WAN
organisation Google
organisation SecurityAffairs
organisation Catalyst
organisation API
infrastructure 20.9.9
infrastructure 20.12.7
infrastructure 20.15.4
infrastructure 20.15.5
infrastructure 20.18.3
infrastructure 26.1.1
organisation Cisco Catalyst SD-
organisation Cisco Releases Security Updates
organisation APT
organisation EDR
organisation Mandiant
organisation Cisco Technical Assistance Centers
organisation vSmart
organisation the Cisco Technical Assistance Center
organisation TAC
‎June 29, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Cisco SD-WAN Zero-Day Exploit in its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by June 29, 2026.
tactic T1588.006 - Vulnerabilities
attribution Cisco Catalyst
attribution Known Exploited
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎June 2026
Threat actors exploited a zero-day vulnerability in Cisco Catalyst SD-WAN software.
infrastructure 20.9.9
infrastructure 20.12.7
infrastructure 20.15.4
infrastructure 20.15.5
infrastructure 20.18.3
infrastructure 26.1.1
observable 20.15.5.3
observable 26.1.1.2
observable 20.9.9.2
observable 20.15.4.5
observable 20.18.3.1
observable 20.12.7.2
organisation Cisco Catalyst SD-WAN Release
organisation Cisco Catalyst SD-
organisation Cisco
Tactical Metrics
Metrics
infrastructure
‎20.9.9
Software Version
Metrics
infrastructure
‎20.12.7
Software Version
Metrics
infrastructure
‎20.15.4
Software Version
Metrics
infrastructure
‎20.15.5
Software Version
Metrics
infrastructure
‎20.18.3
Software Version
Metrics
infrastructure
‎26.1.1
Software Version
Metrics
infrastructure
6,000
Wan Devices