Google's Mandiant threat intelligence team reported this week that attackers began exploiting a critical flaw in Cisco Catalyst SD-WAN as early as March, roughly two months before Cisco disclosed the vulnerability in early June. The vulnerability, assigned as CVE-2026-20245, allows an attacker who already has administrator credentials on an affected system to escalate privileges to root-level access. The vulnerability stems from insufficient input validation and affects the command line interface of Cisco Catalyst SD-WAN Controller. Cisco released final fixes for affected versions June 12 after initially disclosing the flaw eight days before, citing limited exploit activity. The company described CVE-2026-20245 as a flaw that attackers could exploit only if they already had valid netadmin privileges or if they chained the vulnerability with two previously disclosed zero-days in Catalyst SD-WAN Controller — CVE-2026-20182 or CVE-2026-20127. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to its catalog of known exploited vulnerabilities on June 4. The agency gave Federal Civilian Executive Branch (FCEB) a June 23 deadline to address the flaw or to stop using affected systems until they did. In a blog post this week, Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan said they discovered CVE-2026-20245 when investigating attacks that targeted SD-WAN infrastructure at a service provider between late 2025 and January 20...
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
Dark Reading
·Jai Vijayan
·Published Jun 24, 2026
·Updated
Affected Software
1 affected component
Cisco Catalyst SD-WAN Controller
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a critical vulnerability in Cisco Catalyst SD-WAN before its official disclosure.
2
What specific vulnerability is addressed in the article?
The vulnerability discussed is CVE-2026-20245, affecting the Cisco Catalyst SD-WAN Controller.
3
Who reported the exploitation of this Cisco SD-WAN flaw?
The exploitation was reported by Google's Mandiant threat intelligence team.
4
When did the exploitation of the Cisco SD-WAN flaw begin?
The exploitation began in March, two months prior to the vulnerability's disclosure in June.
5
What are the potential implications of this security flaw?
The vulnerability allows attackers to compromise the Cisco Catalyst SD-WAN, potentially leading to unauthorized access or data breaches.