Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposureembedded-device-vulnerabilityprivilege-escalation-method

Cisco Catalyst SD-WAN Manager Zero-Day Exploited for Root Command Execution

Updated 3d agoFirst seen Jun 5, 202611 sources

Cisco disclosed active exploitation of CVE-2026-20245, a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager that lets an authenticated attacker with netadmin privileges upload a crafted file and execute arbitrary commands as root. The vulnerability affects all deployment models, including on-premises, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP environments, and Cisco said attackers have already used it in limited incidents to push unauthorized configuration changes to SD-WAN edge devices.

Cisco said the flaw stems from insufficient validation and sanitization of user-supplied input in the CLI processing path, and warned that attackers may obtain the required privileges with valid credentials or by chaining previously disclosed bugs such as CVE-2026-20182 or CVE-2026-20127. No dedicated patch or workaround was available at disclosure, so Cisco urged customers to upgrade to software versions that fix earlier exploited issues, review indicators of compromise such as suspicious entries in /var/log/scripts.log, preserve forensic evidence, collect diagnostics with the command:

request admin-tech

and contact Cisco TAC if compromise is suspected.

Share:
Cisco Catalyst SD-WAN Manager Zero-Day Exploited for Root Command Execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 5, 20264d ago

Cisco publishes IOCs and mitigation guidance for compromised systems

Alongside the disclosure, Cisco shared indicators of compromise such as suspicious entries in /var/log/scripts.log and advised customers to preserve forensic evidence, collect admin-tech data, and contact Cisco TAC for compromise assessment. Cisco also recommended upgrading to software versions that already fix the previously exploited CVE-2026-20182 while awaiting a dedicated fix for CVE-2026-20245.

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Cisco discloses actively exploited CVE-2026-20245 with no patch yet

Cisco publicly disclosed CVE-2026-20245, a high-severity command injection and privilege-escalation flaw in Cisco Catalyst SD-WAN Manager that can let an authenticated attacker with netadmin privileges execute commands as root. At disclosure, Cisco said the vulnerability was being actively exploited in the wild, affected all deployment models, and had no dedicated patch or workaround available.

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Cisco receives Mandiant report of SD-WAN zero-day exploitation

Cisco said it learned in June of active exploitation of CVE-2026-20245 in Catalyst SD-WAN Manager after receiving a report from Mandiant. The observed activity included limited incidents in which attackers pushed unauthorized configuration changes to SD-WAN edge devices.

Cisco warns of unpatched SD-WAN zero-day exploited in attacks
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.