Cisco SD-WAN make-me-root bug under attack

https://image.theregister.com/5244089.jpg?imageId=5244089&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Second Catalyst SD-WAN Manager flaw exploited as an 0-day this month

Cisco today issued a fix for a Catalyst SD-WAN Manager bug that attackers have already spotted and exploited to get root privileges, according to both the networking vendor and the feds.

The vulnerability, tracked as CVE-2026-20262, is in the web UI of Cisco Catalyst SD-WAN Manager, and exists because the software is not properly validating user-supplied input during a file upload process.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system,” the vendor warned in a Monday security advisory. “A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root.”

There is one caveat: to exploit this bug, the attacker must have valid credentials with at least a lower-privileged,...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more