News Article · Jun 8, 2026 at 1:11 PM
3 min read 0
Member
Cisco SD-WAN Zero-Day Exploited in Attacks, No Patch Available Yet
Security #Cisco #SD-WAN #zero-day #CVE-2026-20245 #vulnerability #active exploitation #privilege escalation

Cisco SD-WAN Zero-Day Exploited in Attacks, No Patch Available Yet

Attackers are exploiting a high-severity zero-day in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) with no patch in sight. The flaw requires netadmin credentials but allows root-level command execution. It is the sixth SD-WAN vulnerability under active attack this year.

Listen to this article 4 min

A high-severity zero-day vulnerability in Cisco's Catalyst SD-WAN Manager is under active exploitation, and the networking giant has not yet released a patch. Tracked as CVE-2026-20245, the bug carries a CVSS score of 7.8 out of 10 and affects all versions of the software across on-premises, cloud, and FedRAMP-certified deployments, Cisco confirmed on June 4.

The flaw is a validation error that lets an authenticated local attacker with netadmin privileges upload a specially crafted file to an affected system. Successful exploitation grants root-level command execution. Cisco said it became aware of attacks in June 2026 and noted that the only known exploitation path requires netadmin credentials, which can be obtained through prior compromise of two other SD-WAN bugs: CVE-2026-20182 and CVE-2026-20127.

Sixth SD-WAN Zero-Day Under Fire in 2026

This is the sixth SD-WAN vulnerability listed as under active attack since the start of 2026, and the second zero-day in two months. In May, Cisco disclosed CVE-2026-20182, a max-severity bug in the Catalyst SD-WAN Controller and Manager, and confirmed attackers exploited it before a patch was issued. In April, the U.S. Cybersecurity and Infrastructure Security Agency ordered federal agencies to patch three other SD-WAN Manager flaws within four days: CVE-2026-20128, CVE-2026-20133, and CVE-2026-20122. Cisco fixed those in late February. In February itself, a Five Eyes joint intelligence alert urged defenders to patch CVE-2026-20127, an improper authentication flaw, plus an older bug CVE-2026-20775, warning of root takeover risk.

  • Cisco recommends customers upgrade to fixed software released in May 2026 for CVE-2026-20182 as a protective measure.
  • No timeline has been provided for a patch for CVE-2026-20245; Cisco advises affected customers to contact TAC for assistance.
  • The attack chain for the current zero-day requires netadmin credentials, which attackers can obtain via the earlier flaws or through credential theft.
  • The Five Eyes warning in February stated attackers were compromising SD-WANs to add rogue peers and achieve persistent root access.

Persistent Threat to Global SD-WAN Deployments

The repeated exploitation of SD-WAN flaws underscores the high value attackers place on network management platforms. The UK's National Cyber Security Centre warned in February that malicious actors are targeting Cisco Catalyst SD-WAN used by organizations globally. Once inside, they conduct follow-on actions to gain root access and maintain persistence. Cisco has not disclosed the scope of current attacks or the initial compromise vector beyond the credential requirement. The vendor declined to answer questions from The Register, instead issuing a statement urging customers to upgrade to fixed software from May for the related CVE-2026-20182. Until a patch for CVE-2026-20245 is released, organizations should enforce strict access controls for netadmin accounts, monitor for suspicious file uploads, and implement network segmentation to limit lateral movement. A proof-of-concept exploit for another critical Cisco bug, CVE-2026-20230 in Unified Communications Manager, was also disclosed this week, though not yet seen in attacks.

Fact check

  • CVE-2026-20245 is a high-severity zero-day vulnerability in Cisco Catalyst SD-WAN Manager being actively exploited.

    verified · source

  • The flaw carries a CVSS score of 7.8 and affects all deployment types including on-prem, cloud, and FedRAMP.

    verified · source

  • This is the sixth SD-WAN vulnerability listed as under active attack since the start of 2026.

    reported · source

  • Attackers need netadmin credentials to exploit CVE-2026-20245, which can be obtained via CVE-2026-20182 or CVE-2026-20127.

    reported · source

  • In February 2026, a Five Eyes joint intelligence alert warned defenders to patch CVE-2026-20127 and an older bug or risk root takeover.

    reported · source

Source reporting (2)

0 Comments

No comments yet

Be the first to share your thoughts on this article.