• News/
  • bleepingcomputer-20260605062420

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 5, 2026
·
Updated

On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root. "An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user," the company explained. "To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods," it added. "Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices." Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard. Cisco's Product Security Incident R...

Read full article

Affected Software

4 affected components
Cisco Catalyst SD-WAN Manager (On-Prem Deployment)
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN Cloud-Pro)
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN Cloud (Cisco Managed))
Cisco Catalyst SD-WAN Manager (Cisco SD-WAN for Government (FedRAMP))

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity zero-day vulnerability in Cisco Catalyst SD-WAN Manager that is currently being exploited in attacks.

2

What security implications are discussed in the article?

The zero-day flaw allows for root privilege escalation, posing significant risks to affected systems and networks.

3

What is the tracked identifier for the vulnerability?

The vulnerability is tracked as CVE-2026-20245.

4

Which products are affected by this zero-day vulnerability?

The affected products include all deployment types of Cisco Catalyst SD-WAN Manager, including On-Prem, Cloud-Pro, Cisco Managed, and FedRAMP.

5

Is there a patch available for this vulnerability?

No, Cisco has warned that this zero-day vulnerability remains unpatched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203