VORANT. Threat Intelligence Sign in Get the full feed

Cisco Catalyst SD-WAN flaw actively exploited

high vulnerability

CVE-2026-20262, a vulnerability in Cisco Catalyst SD-WAN allowing data integrity compromise, is under active exploitation across multiple product versions.

Cisco has disclosed CVE-2026-20262, a vulnerability affecting multiple versions of Catalyst SD-WAN that enables attackers to compromise data integrity. The vendor has confirmed that this vulnerability is being actively exploited in the wild, elevating the urgency for affected organizations to apply patches immediately.

Affected versions span a wide range of Catalyst SD-WAN releases, including 20.9.x, 20.12.x, 20.15.x, 20.18.x, and 26.1.x series. Organizations running vulnerable versions should prioritize patching to the fixed releases specified in Cisco's security advisory. The active exploitation status indicates that threat actors have weaponized this vulnerability and are targeting exposed Catalyst SD-WAN deployments.

Mentioned in this report

Vulnerabilities CVE-2026-20262KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0756

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free