Skip to content
Zero-dayOngoing

Cisco SD-WAN Manager zero-day exploited in the wild (CVE-2026-20245)

Cisco warned that an unpatched high-severity zero-day in Catalyst SD-WAN Manager (CVE-2026-20245) was being actively exploited to execute arbitrary commands and escalate to root, after Mandiant reported a limited number of real-world attacks.

Victim
Cisco Catalyst SD-WAN Manager
Threat actorUnknown
CVECVE-2026-20245

On 5 June 2026, Cisco warned that an unpatched, high-severity zero-day in its Catalyst SD-WAN Manager โ€” tracked as CVE-2026-20245 โ€” was being actively exploited in the wild. The flaw stems from insufficient validation of user-supplied input and lets an attacker upload a crafted file to perform command injection and execute arbitrary commands as root.

What happened

Cisco's Product Security Incident Response Team (PSIRT) said it became aware of exploitation after Google Cloud's Mandiant reported the issue, confirming a limited number of cases in which the flaw was abused to push a configuration change to edge devices. To exploit the vulnerability, an attacker first needs netadmin privileges on the targeted system โ€” obtainable with compromised credentials or by chaining other SD-WAN flaws such as CVE-2026-20182 or CVE-2026-20127.

The vulnerability affects all deployment types, including on-premises, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud, and the FedRAMP-authorised SD-WAN for Government. At disclosure, Cisco had not released a patch for CVE-2026-20245 and advised customers to move to the software fixed for CVE-2026-20182.

Why it matters

SD-WAN managers sit at the control plane of enterprise networks, orchestrating configuration for fleets of edge devices. Root code execution there turns a single compromised management console into leverage over an entire network's routing โ€” and this marks one of a string of SD-WAN zero-days Cisco has had to address in 2026, several exploited before any fix was available.

Timeline

  1. Cisco discloses CVE-2026-20245, confirms active exploitation, and notes no patch is yet available.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/
  2. securityweek.comhttps://www.securityweek.com/cisco-warns-of-7th-sd-wan-zero-day-exploited-in-2026/
  3. theregister.comhttps://www.theregister.com/security/2026/06/05/yet-another-cisco-sd-wan-0-day-under-attack-and-no-patch-in-sight/5251855
  4. cybersecuritydive.comhttps://www.cybersecuritydive.com/news/cisco-zero-day-flaw-sd-wan-exploited/822138/

Related incidents