• News/
  • darkreading-20260624211641

Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure

Dark Reading
·
Jai Vijayan
·
Published Jun 24, 2026
·
Updated

Google's Mandiant threat intelligence team reported this week that attackers began exploiting a critical flaw in Cisco Catalyst SD-WAN as early as March, roughly two months before Cisco disclosed the vulnerability in early June. The vulnerability, assigned as CVE-2026-20245, allows an attacker who already has administrator credentials on an affected system to escalate privileges to root-level access. The vulnerability stems from insufficient input validation and affects the command line interface of Cisco Catalyst SD-WAN Controller. Cisco released final fixes for affected versions June 12 after initially disclosing the flaw eight days before, citing limited exploit activity. The company described CVE-2026-20245 as a flaw that attackers could exploit only if they already had valid netadmin privileges or if they chained the vulnerability with two previously disclosed zero-days in Catalyst SD-WAN Controller — CVE-2026-20182 or CVE-2026-20127. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to its catalog of known exploited vulnerabilities on June 4. The agency gave Federal Civilian Executive Branch (FCEB) a June 23 deadline to address the flaw or to stop using affected systems until they did. In a blog post this week, Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan said they discovered CVE-2026-20245 when investigating attacks that targeted SD-WAN infrastructure at a service provider between late 2025 and January 20...

Read full article

Affected Software

1 affected component
Cisco Catalyst SD-WAN Controller

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical vulnerability in Cisco Catalyst SD-WAN before its official disclosure.

2

What specific vulnerability is addressed in the article?

The vulnerability discussed is CVE-2026-20245, affecting the Cisco Catalyst SD-WAN Controller.

3

Who reported the exploitation of this Cisco SD-WAN flaw?

The exploitation was reported by Google's Mandiant threat intelligence team.

4

When did the exploitation of the Cisco SD-WAN flaw begin?

The exploitation began in March, two months prior to the vulnerability's disclosure in June.

5

What are the potential implications of this security flaw?

The vulnerability allows attackers to compromise the Cisco Catalyst SD-WAN, potentially leading to unauthorized access or data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203