NCSC-2026-0199 [1.00] [M/H] Vulnerability fixed in Cisco Catalyst SD-WAN Manager
Cisco has fixed a vulnerability in Cisco Catalyst SD-WAN Manager. The vulnerability is in the web user interface of Cisco Catalyst SD-WAN Manager and concerns a directory traversal flaw. This is caused by improper input validation during the file upload process. An authenticated attacker can create or overwrite arbitrary files on the underlying system. Upon successful exploitation, the attacker can gain root-level access, affecting system integrity. Cisco reports having information that the vulnerability has been exploited in a limited manner.
CSIRTS triage
- What
- The vulnerability is a directory traversal flaw in the web user interface.
- Who is affected
- Authenticated attackers can exploit this vulnerability to gain root-level access.
- Urgency
- Remediation is urgent due to confirmed limited exploitation.
- Action
- Apply the latest patches provided by Cisco.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Catalyst SD-WAN Manager
Get an email when a new Catalyst SD-WAN Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0199
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-20262Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 98% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20262 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumexploitedCisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerabilitycisco-psirt
- criticalexploitedCVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerabilitycisa-kev
Recent advisories for Cisco Catalyst SD-WAN
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCisco Catalyst SD-WAN Manager Information Disclosure Vulnerabilitycisco-psirt · 2026-08-07
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund · 2026-08-06
- unknownNCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WANncsc-nl · 2026-08-06
- highCVE-2026-20313: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- highCVE-2026-20312: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21