惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
I
InfoQ
H
Help Net Security
GbyAI
GbyAI
博客园 - 叶小钗
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
Y
Y Combinator Blog
L
LangChain Blog
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
博客园 - Franky
D
Docker
Jina AI
Jina AI
罗磊的独立博客

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day ...
Abinaya · 2026-06-16 · via Cyber Security News

Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise network environments worldwide.

The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a CVSS score of 6.5 and stems from improper validation of user-supplied input during file upload operations.

According to Cisco, attackers with valid credentials and write-level access can exploit this flaw to upload crafted files to targeted systems. Once exploited, the vulnerability allows an attacker to create or overwrite files anywhere on the underlying operating system.

Cisco SD-WAN vManage Vulnerability

This capability can be leveraged to deploy malicious payloads, including web shells, and potentially escalate privileges to root level, significantly increasing the severity of the attack.

Cisco’s Product Security Incident Response Team (PSIRT) confirmed that the vulnerability has already been observed in limited real-world exploitation as of June 2026.

This places the flaw in the category of zero-day vulnerabilities, where attackers can exploit it before widespread patching occurs.

The issue affects all deployment models of Cisco Catalyst SD-WAN Manager, including on-premises systems, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP environments.

Notably, there are no available workarounds, making immediate patching the only effective mitigation. Security researchers highlight that internet-exposed SD-WAN management interfaces are the most at risk.

Attackers can exploit exposed API endpoints by crafting HTTP requests to upload malicious files. One example includes uploading a WAR file to sensitive directories using directory traversal techniques. Cisco has provided specific Indicators of Compromise (IOCs) to help organizations detect potential exploitation.

Suspicious activity may appear in log files such as:

  • vmanage-server.log showing unauthorized file uploads, including paths like “../../../../var/lib/wildfly/standalone/deployments/suspicious.war”.
  • vmanage-appserver.log indicating deployment of unexpected WAR files.
  • serviceproxy-access.log captures HTTP POST requests to malicious endpoints such as “/suspicious/index.jsp”.

These logs suggest post-exploitation activity, where attackers deploy and interact with malicious applications within the system.

Cisco clarified that this vulnerability does not directly affect SD-WAN traffic handling or connectivity.

However, compromise of the management plane could allow attackers to manipulate configurations or maintain persistent access. To address the issue, Cisco has released patched versions across multiple software branches.

Affected users are strongly advised to upgrade to fixed releases such as 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2, depending on their deployment.

Organizations are also encouraged to audit logs, restrict external access to management interfaces, and use the “request admin-tech” command to collect diagnostic data before engaging Cisco TAC for incident response support.

This vulnerability was identified during internal security testing. However, its rapid transition to active exploitation highlights the ongoing risk posed by exposed management interfaces and insufficient input validation mechanisms.

With no workaround available and active attacks underway, timely patching and continuous monitoring remain critical to reducing exposure.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.