logo

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)

ID: b029b96d-9953-5fc4-8cdb-e68bb73782a6

STIX ID: report--b029b96d-9953-5fc4-8cdb-e68bb73782a6

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Zeljka Zorz

...
...

Cisco disclosed a 0-day privilege escalation (CVE-2026-20245) in Catalyst SD-WAN Manager that enables authenticated local attackers (requiring netadmin privileges or chaining from other vulnerabilities) to achieve root command execution by uploading crafted files; limited exploitation has been observed causing configuration changes to edge devices. Cisco credited Mandiant, released indicators of compromise and guidance to collect admin-tech logs before upgrading, and is rolling out patches with no workaround currently available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.