CVE-2026-20310
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20310 is a critical improper link resolution before file access (CWE-59) vulnerability affecting Cisco Catalyst SD-WAN Controller and SD-WAN Manager software. Discovered through Cisco's internal security review (including frontier AI-assisted testing), it was publicly disclosed on August 5, 2026. The vulnerability affects a broad range of software versions spanning releases 17.x through 26.x across both the Controller and Manager components, covering all deployment types (on-premises, Cloud-Pro, Cloud Managed, and FedRAMP). It carries a CVSS v3.1 base score of 9.1 (Critical) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access, also known as 'Link Following'), meaning the affected software fails to properly validate or restrict symbolic link or hard link targets before performing file operations. An authenticated attacker with high-level network privileges can craft symlinks or hard links that redirect file access operations to unintended resources, potentially outside the intended directory scope. Attack patterns associated with this vulnerability include symlink attacks (CAPEC-132), using malicious files (CAPEC-17), and manipulating web input to file system calls (CAPEC-76). The vulnerability requires no user interaction and has a changed scope, meaning successful exploitation can impact resources beyond the vulnerable component itself (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with high privileges to read, modify, or delete sensitive files and potentially execute arbitrary code with elevated permissions on the affected SD-WAN Controller or Manager. The changed scope means the impact extends beyond the directly vulnerable component, potentially compromising the entire SD-WAN infrastructure including configuration data, credentials, and network routing policies. Given the central role of SD-WAN controllers and managers in enterprise network orchestration, compromise could enable lateral movement across the managed WAN environment and expose sensitive network topology and credential information (Cisco Advisory, Feedly).

Exploitability

As of the disclosure date, Cisco PSIRT is not aware of any public proof-of-concept exploit code or active malicious exploitation of this vulnerability in the wild (Cisco Advisory). The NVD SSVC assessment indicates exploitation is 'none' and the attack is not automatable. The EPSS score is approximately 0.37–0.39%, placing it in the 32nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (ID 317869) and Nessus (ID 333337) (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Cisco Catalyst SD-WAN Controller or Manager instances running vulnerable software versions (17.x through 26.1.x) using network scanning or Shodan/Censys queries targeting SD-WAN management interfaces.
  2. Authentication: Obtain high-privilege credentials for the SD-WAN management interface through credential theft, phishing, or reuse of compromised administrative accounts.
  3. Symlink/Hard Link Creation: Using authenticated access to the SD-WAN system, create a malicious symbolic link or hard link within a directory accessible to the SD-WAN process, pointing to a sensitive target file (e.g., system configuration files, credential stores, or OS-level files outside the intended path).
  4. Trigger File Access: Invoke an SD-WAN operation or API call that causes the application to follow the crafted link and perform a file read, write, or execute operation on the unintended target resource.
  5. Achieve Objective: Depending on the target file and operation, read sensitive configuration or credentials, overwrite critical files to achieve persistence or privilege escalation, or execute arbitrary code with the permissions of the SD-WAN service account, potentially compromising the broader SD-WAN infrastructure (Cisco Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected symbolic links or hard links in SD-WAN application directories pointing to sensitive system files or directories outside the expected path; newly created or modified files in sensitive OS directories (e.g., /etc/, /root/) with timestamps correlating to SD-WAN process activity.
  • Logs: SD-WAN application logs showing file access operations to unexpected paths or directories; OS-level audit logs (auditd) recording symlink creation or unusual file open calls by the SD-WAN service account.
  • Process: Unusual child processes spawned by the SD-WAN Controller or Manager process (e.g., shell commands, file copy utilities); SD-WAN service account accessing files outside its normal operational directories.
  • Network: Unexpected outbound connections from SD-WAN Controller or Manager hosts to external IPs following administrative login events; anomalous API calls to SD-WAN management interfaces from unusual source IPs or at unusual times.

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Customers should upgrade to the following fixed releases: SD-WAN 20.9 → 20.9.10; SD-WAN 20.12 (and 20.10, 20.11) → 20.12.8.1; SD-WAN 20.15 (and 20.13, 20.14) → 20.15.6; SD-WAN 20.18 (and 20.16) → 20.18.4; SD-WAN 26.1 → 26.1.2. Releases earlier than 20.9 have reached End of Software Maintenance and customers must migrate to a supported release. As interim hardening measures, restrict administrative access to SD-WAN management interfaces to only trusted personnel and networks, and monitor file system activity on SD-WAN controllers and managers for suspicious symlink or hard link creation (Cisco Advisory).

Community reactions

Cisco's advisory was widely covered by security media outlets including The Hacker News, SecurityWeek, GBHackers, CyberSecurityNews, and SOCRadar, with coverage noting the breadth of affected versions and the critical severity of the SD-WAN hardening release bundle (The Hacker News, SecurityWeek). Qualys published a threat protection bulletin specifically covering CVE-2026-20310 alongside related SD-WAN CVEs. CISA included the advisory in its weekly bulletin (SB26-222), and government CERTs including AUSCERT and Singapore's CSA issued alerts. Community sentiment highlighted the unusually large number of affected version strings and the use of AI-assisted internal testing as a notable aspect of Cisco's disclosure (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20304CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20303CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20310CRITICAL9.1
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20312HIGH8.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20313HIGH7.7
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management