Cisco has warned that CVE-2026-20245, a high-severity vulnerability in its Catalyst SD-WAN Manager platform, is being actively exploited in the wild with no patch available. It is the seventh SD-WAN zero-day to come under attack in 2026.
Root command execution from netadmin role
The flaw, which carries a CVSS score of 7.8, lives in the SD-WAN Manager command-line interface and lets an authenticated, local attacker upload a crafted file to execute arbitrary commands as root. "An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user," Cisco said in its Thursday advisory. Exploitation requires netadmin privileges, which attackers are obtaining via stolen credentials or by chaining the recent CVE-2026-20182 authentication bypass that Rapid7 disclosed last month.
Mandiant credited with discovery
Cisco's Product Security Incident Response Team (PSIRT) became aware of the issue in June after Google Cloud cybersecurity subsidiary Mandiant reported the flaw. Researchers Chester Sng, Pete Boonyakarn and Logeswaran Nadarajan are credited with the disclosure. Every SD-WAN deployment type is in scope: On-Prem, Cloud-Pro, Cisco-Managed Cloud and the FedRAMP-authorised SD-WAN for Government variant. Formerly known as SD-WAN vManage, the platform manages up to 6,000 Catalyst SD-WAN devices from a single dashboard. Cisco said it has already seen limited cases where exploitation resulted in configuration changes pushed to edge devices, and warned that internet-exposed systems face heightened risk.
Seventh SD-WAN zero-day of 2026
CVE-2026-20245 joins a list of six other actively exploited SD-WAN flaws this year, including CVE-2026-20182, CVE-2026-20127, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133 and CVE-2022-20775. There is no patch or workaround for the new flaw. Cisco recommends customers ensure they have applied the May 14 fixes for CVE-2026-20182, scan "/var/log/scripts.log" for suspicious vScript entries that upload tenant configuration data to vSmart controllers, and harden internet-facing instances.
The disclosure follows Microsoft's record June Patch Tuesday, the RoguePlanet Defender bypass and CISA's addition of the BerriAI LiteLLM flaw to its KEV catalogue.
Reporting based on coverage from Cisco Security Advisory, BleepingComputer and The Hacker News.
