Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposureembedded-device-vulnerabilityprivilege-escalation-method

Cisco SD-WAN Manager Command Injection Exploited for Root-Level Device Changes

Updated 17d agoFirst seen Jun 5, 20269 sources

Cisco disclosed a critical command injection flaw in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) that is being actively exploited in the wild, allowing an authenticated local attacker with netadmin privileges to execute arbitrary commands as root. The vulnerability is caused by insufficient validation of file-transfer payloads in the CLI, and Cisco said observed exploitation has already resulted in unauthorized configuration changes being pushed from the manager to edge devices, raising the risk of broader network compromise in affected SD-WAN environments.

Cisco also warned the issue could be chained with the previously disclosed authenticated privilege-escalation bug CVE-2026-20182 to obtain the required access level before triggering command execution. At the time of disclosure, no standard software fix was available; administrators were advised to review logs, inspect scripts.log for suspicious activity, and work with Cisco Technical Assistance Center for mitigations and workarounds while assessing whether managed edge infrastructure had been altered.

Share:
Cisco SD-WAN Manager Command Injection Exploited for Root-Level Device Changes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 5, 202617d ago

Cisco reports active exploitation of CVE-2026-20245

Cisco disclosed that CVE-2026-20245, a critical command injection flaw in Cisco Catalyst SD-WAN Manager, was being actively exploited in the wild as of June 2026. Observed exploitation led to configuration changes being pushed to edge devices, and Cisco said no standard patch was yet available while mitigations were provided through TAC.

Cisco SD-WAN Vulnerability Exploited in the Wild
Jun 4, 202618d ago

Acer releases urgent firmware update for Connect W6x devices

Acer released firmware version W6x_GBL_2.00.000008 or later for affected Connect W6x consumer wireless devices. The update fixes critical flaws including CVE-2026-49197 and CVE-2026-49199, along with three additional high-severity vulnerabilities.

Acer Router Flaw: Critical Authentication Bypass

Multiple Acer vulnerability CVE records are published

On June 4, 2026, CVE records were published for several Acer issues, including CVE-2026-49190, CVE-2026-49193, CVE-2026-50206, CVE-2026-50207, and CVE-2026-50209. The entries describe impacts ranging from command injection and unauthorized command execution to public telemetry exposure and MDM endpoint takeover.

CVE-2026-50206 - VPN Command Injection Vulnerability
Jun 3, 202619d ago

Acer posts security advisory for upcoming firmware update

An Acer community security advisory about an upcoming firmware update for the Acer Connect M6E 5G Portable WiFi Router was published. This advisory is cited by later CVE records tied to multiple Acer vulnerabilities.

Security Advisory: Upcoming Firmware Update for Acer Connect M6E 5G Portable WiFi Router - Acer Community
Apr 6, 20263mo ago

Cisco publishes SD-WAN Manager privilege escalation advisory

Cisco published a security advisory for an authenticated privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager. The advisory corresponds to CVE-2026-20182, which was later noted as chainable with CVE-2026-20245.

Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.