logo

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

ID: 787c5ec0-074c-508c-b97d-0b9a3f7405cd

STIX ID: report--787c5ec0-074c-508c-b97d-0b9a3f7405cd

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Sergiu Gatlan

...
...

Cisco warns of an actively exploited high-severity zero-day (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager (vManage) that allows local attackers with netadmin privileges to perform command injection and escalate to root. Cisco observed limited exploitation cases, provided an IOC log example showing attempted tenant list uploads, and advised customers to open TAC cases and apply mitigations while patches are not yet available; the issue may be chained with other recently exploited SD-WAN CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.