One of 6 live-CVE / KEV wins
“Is CVE-2026-20262 on CISA's known-exploited list? What is it, and what should I be hunting for?”
I don't have information about CVE-2026-20262 in my training data. The number suggests a 2026 date, beyond my knowledge cutoff. Check CISA's KEV catalog and the NVD directly, then hunt for the affected software and exploitation patterns once you confirm the details.
Yes, CVE-2026-20262 is on CISA’s KEV catalog. It’s a directory/path-traversal vulnerability (CWE-22) in Cisco Catalyst SD-WAN Manager that lets an authenticated remote attacker create or overwrite arbitrary files. Added to KEV 2026-06-15; federal remediation due 2026-06-29. Hunt for unusual file writes from SD-WAN Manager processes, path-traversal sequences in HTTP requests to Manager instances, and processes spawned from unexpected locations.
cited: CISA KEV: CVE-2026-20262 (Cisco Catalyst SD-WAN Manager)