logo

Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks

ID: 93ccc4a8-ff4d-5a3a-993f-44f1c8fee103

STIX ID: report--93ccc4a8-ff4d-5a3a-993f-44f1c8fee103

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Do Son

...
...

Critical command-injection vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager permits authenticated users with netadmin privileges to execute arbitrary commands as root by uploading crafted files; exploitation observed in the wild (June 2026) has caused configuration changes on edge devices. Vendor patches are not yet available — administrators should audit local logs (e.g., scripts.log) and engage Cisco TAC for isolation and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.