HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical ThreatIntel

Zero‑Day in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20245) Actively Exploited for Root Access

Cisco has confirmed active exploitation of CVE‑2026‑20245, a zero‑day in its Catalyst SD‑WAN Manager that enables privilege escalation to root. All deployment models are vulnerable and no patch is yet available, creating immediate supply‑chain risk for enterprises that depend on Cisco SD‑WAN services.

LiveThreat™ Intelligence · 📅 June 05, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
bleepingcomputer.com

Zero‑Day in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20245) Enables Root Privilege Escalation

What It Is — Cisco disclosed a high‑severity, unpatched zero‑day (CVE‑2026‑20245) in the Catalyst SD‑WAN Manager that allows a local attacker with net‑admin rights to execute arbitrary commands as root. Active exploitation has been observed in the wild.

Exploitability — Exploits are confirmed in the wild; a proof‑of‑concept exists via crafted file upload. CVSS v3.1 score ≈ 9.8 (Critical).

Affected Products — Cisco Catalyst SD‑WAN Manager (on‑prem, SD‑WAN Cloud‑Pro, Cisco‑Managed Cloud, FedRAMP‑authorized SD‑WAN).

TPRM Impact — Organizations that rely on Cisco SD‑WAN as a managed service or embed it in their own network stack face immediate risk of network control compromise, potential downstream service disruption for customers, and exposure of internal traffic flows.

Recommended Actions

  • Verify whether any Cisco SD‑WAN Manager instances are running a vulnerable version.
  • Apply the interim mitigation: upgrade to the version that patches CVE‑2026‑20182 (released May 14) and restrict net‑admin access.
  • Collect and review /var/log/scripts.log for the IOC pattern shown by Cisco.
  • Open a case with Cisco TAC and obtain the latest admin‑tech files for forensic analysis.
  • Prioritize patch deployment as soon as Cisco releases a fix for CVE‑2026‑20245.

Source: BleepingComputer – Cisco SD‑WAN Zero‑Day Exploited

📰 Original Source
https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.