Cisco Catalyst SD-WAN Manager root privilege escalation flaw (CVE-2026-20245)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-20245 in Cisco Catalyst SD-WAN Manager is an actively exploited high-severity vulnerability that can let an authenticated local attacker with netadmin privileges upload a crafted file and execute arbitrary commands as root. Cisco says the issue affects On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), and that exploitation has already caused configuration changes pushed to edge devices in limited cases. Cisco also said no patches or mitigations are currently available and advised checking /var/log/scripts.log for IoCs.
Related Happenings
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
Campaign
H score38
First: 25.06.2026 17:15
Last: 25.06.2026 17:15
Sources 1
How related:
From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices.
About this happening:
An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
CampaignHow related: From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices.
About this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector Action
H score32
First: 16.06.2026 09:05
Last: 16.06.2026 09:05
Sources 1
About this happening:
CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector ActionAbout this happening: CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
Cisco Catalyst SD-WAN Manager actively exploited file upload overwrite flaw (CVE-2026-20262)
Vulnerability
H score24
First: 15.06.2026 20:12
Last: 15.06.2026 20:12
Sources 1
About this happening:
Cisco Catalyst SD-WAN Manager was patched for CVE-2026-20262 after attackers used it to create or overwrite files and escalate to root across all deployment type...
Cisco Catalyst SD-WAN Manager actively exploited file upload overwrite flaw (CVE-2026-20262)
VulnerabilityAbout this happening: Cisco Catalyst SD-WAN Manager was patched for CVE-2026-20262 after attackers used it to create or overwrite files and escalate to root across all deployment type...
Cisco Unified CM SSRF root-privilege flaw (CVE-2026-20230)
Vulnerability
H score49
First: 04.06.2026 14:09
Last: 04.06.2026 14:09
Sources 1
About this happening:
CVE-2026-20230 exposes Cisco Unified CM systems with WebDialer enabled to remote SSRF abuse that can lead to root-level compromise. The flaw can be triggered w...
Cisco Unified CM SSRF root-privilege flaw (CVE-2026-20230)
VulnerabilityAbout this happening: CVE-2026-20230 exposes Cisco Unified CM systems with WebDialer enabled to remote SSRF abuse that can lead to root-level compromise. The flaw can be triggered w...
Latest development: 26.06.2026 22:43
Cisco released a patch for CVE-2026-20230 in Cisco Unified Communications Manager Server and warned that the critical server-side request forgery flaw could be exploited remotely and without authentication via specially crafted HTTP requests.
Cisco Secure Workload REST API validation/authentication flaw (CVE-2026-20223)
Vulnerability
H score49
First: 21.05.2026 15:04
Last: 21.05.2026 15:04
Sources 1
About this happening:
Cisco Secure Workload Cluster Software was patched for CVE-2026-20223, a critical REST API flaw that could let attackers gain Site Admin privileges and cross tenan...
Cisco Secure Workload REST API validation/authentication flaw (CVE-2026-20223)
VulnerabilityAbout this happening: Cisco Secure Workload Cluster Software was patched for CVE-2026-20223, a critical REST API flaw that could let attackers gain Site Admin privileges and cross tenan...
Timeline
-
06.06.2026 07:19 6 articles · 1mo ago
Cisco warns that Catalyst SD-WAN Manager CVE-2026-20245 is actively exploited
Initial DisclosureCisco warned that CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, is under active exploitation and can let an authenticated local attacker with netadmin privileges upload a crafted file to execute arbitrary commands as root. Cisco said the flaw affects On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), that limited exploitation has already resulted in configuration changes pushed to edge devices, and that no patches or mitigations are currently available. Cisco also advised checking /var/log/scripts.log for indicators of compromise and credited Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan with discovering and reporting the issue.
Show sources
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — thehackernews.com — 06.06.2026 07:19
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — thehackernews.com — 06.06.2026 07:19
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access — www.bleepingcomputer.com — 25.06.2026 00:29
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access — thehackernews.com — 25.06.2026 08:46
- Cisco SD-WAN Zero-Day Exploited Months Before Patching — www.securityweek.com — 25.06.2026 09:08
- Cisco Vulnerability Exploited Months Before Disclosure, Google Warns — www.infosecurity-magazine.com — 25.06.2026 17:15
-
05.06.2026 09:24 2 articles · 1mo ago
Initial report: Cisco Catalyst SD-WAN Manager root privilege escalation flaw (CVE-2026-20245)
Initial DisclosureCisco Catalyst SD-WAN Manager entered an active exploitation phase after Cisco warned on Thursday that CVE-2026-20245 was being abused as a zero-day for root privilege escalation. The weakness was linked to exploitation seen in June and to malicious file uploads against the management system.
Show sources
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks — www.bleepingcomputer.com — 05.06.2026 09:24
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks — www.bleepingcomputer.com — 05.06.2026 09:24