Skip to main content
See every side of every news story
Published loading...Updated

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Cisco said the flaw lets low-privilege attackers run commands as root and has already caused limited configuration changes on edge devices.

  • On Thursday, Cisco warned of a high-severity, unpatched zero-day in its Catalyst SD-WAN Manager, tracked as CVE-2026-20245, allowing local attackers to execute arbitrary commands and elevate privileges to root user.
  • Cisco stated insufficient validation of user-supplied input caused the flaw; Cisco Talos researchers linked exploitation to threat actor UAT-8616, previously connected to attacks involving CVE-2026-20127.
  • The vulnerability carries a severity score of 7.8 and impacts all deployment types, including On-Prem Deployment and Cisco SD-WAN Cloud; Cisco confirmed limited cases where exploitation pushed configuration changes to edge devices.
  • As no patch is currently available, Cisco advised customers to check SD-WAN logs for indicators of compromise. "For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," the company added.
  • This disclosure follows several recent Catalyst SD-WAN security issues, including CVE-2026-20182 with a severity score of 10; the Cybersecurity and Infrastructure Security Agency has tracked 90 Cisco vulnerabilities abused in the wild over recent years.
Insights by Ground AI

11 Articles

Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

A vulnerability has been discovered in Cisco Catalyst SD-WAN. It allows an attacker to cause an elevation of privileges. Cisco indicates that the vulnerability CVE-2026-20245 is actively exploited. See online: https://www.cert.ssi.gouv.fr/avis/C...

Just recently, malicious actors targeted Cisco's SD-WAN devices. Currently, they are attacking a new gap, warns Cisco.

·Germany
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in New York, United States on Friday, June 5, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal