Back to News
Vulnerabilities

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cyber RTJune 6, 20263 min read
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cisco has identified a high-severity security flaw, CVE-2026-20245, in Catalyst SD-WAN Manager, actively exploited with a CVSS score of 7.8. This vulnerability allows authenticated attackers to execute commands as root by uploading crafted files, requiring netadmin privileges. No patches are available, but users should upgrade their software to address related vulnerabilities. Cisco warns that internet-exposed systems are at heightened risk.

Cisco has issued a warning regarding a high-severity security vulnerability affecting its Catalyst SD-WAN Manager, which is currently being actively exploited. The vulnerability, identified as CVE-2026-20245, has a CVSS score of 7.8 out of 10, indicating a significant security risk. This flaw impacts various deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). The vulnerability arises from a flaw in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. It allows an authenticated, local attacker to execute arbitrary commands with root privileges by uploading a specially crafted file to the affected system. This issue stems from insufficient validation of user-supplied input, which can be exploited to perform command injection attacks and elevate privileges. To exploit this vulnerability, an attacker must have netadmin privileges on the affected system, requiring valid credentials or the exploitation of other vulnerabilities such as CVE-2026-20182 or CVE-2026-20127. Cisco has noted that it is not aware of any successful exploitation by other methods. CVE-2026-20182, with a CVSS score of 10.0, was disclosed by Rapid7 and allows unauthenticated, remote attackers to gain administrative privileges through authentication bypass. Both CVE-2026-20182 and CVE-2026-20127 have been exploited as zero-days, with a threat activity cluster named UAT-8616 linked to the abuse of CVE-2026-20127 since 2023. Cisco's advisory notes limited cases where CVE-2026-20245 exploitation led to configuration changes on edge devices. The vulnerability was discovered and reported by Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan, though the identity of those exploiting it remains unknown. Currently, there are no patches or mitigations available for CVE-2026-20245. Cisco advises customers to upgrade their SD-WAN software to apply fixes released for CVE-2026-20182 on May 14, 2026. Systems exposed to the internet are at increased risk, and users should check for indicators of compromise in the "/var/log/scripts.log" file for specific entries that suggest malicious activity. CVE-2026-20245 is the seventh actively exploited flaw in Cisco SD-WAN this year, following other vulnerabilities such as CVE-2026-20182, CVE-2026-20127, and others. This disclosure comes shortly after Cisco addressed another high-severity flaw in Unified Communications Manager (CVE-2026-20230), which has a proof-of-concept exploit code available but has not been actively exploited. For ongoing updates and exclusive content, Cisco encourages readers to follow them on platforms like Google News, Twitter, and LinkedIn. This proactive communication aims to keep users informed about potential security threats and the measures they can take to protect their systems.