Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026
Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used by the UAT-8616 threat actor, leveraging existing SD-WAN vulnerabilities. Cisco is releasing indicators of compromise and a future patch, highlighting the ongoing risk posed by unpatched network infrastructure.
The vulnerability, tracked as CVE-2026-20245, resides in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager and allows authenticated local attackers to execute arbitrary commands as root. This occurs due to insufficient input validation, enabling attackers to upload crafted files and potentially perform command injection attacks, leading to privilege escalation. Cisco’s advisory notes that ‘netadmin’ privileges are required to exploit the flaw, which can be obtained through compromised credentials or exploiting other vulnerabilities like CVE-2026-20182 or CVE-2026-20127.