Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming from improper input validation, allows attackers to execute arbitrary commands and potentially alter configurations. Cisco is advising customers to upgrade to patched versions to mitigate the risk, highlighting a series of related vulnerabilities that have been exploited in recent months.
Cisco has identified that the unpatched zero-day vulnerability, CVE-2026-20245, is being leveraged by malicious actors to compromise SD-WAN Manager systems. The flaw impacts all deployment types of the software, including On-Prem, Cloud-Pro, Cloud (Managed), and Government (FedRAMP) versions. The vulnerability arises from insufficient validation of user-supplied input, enabling local attackers with low privileges to escalate their permissions to root level. Cisco observed configuration changes being pushed to edge devices as a result of exploitation.
Cisco’s Product Security Incident Response Team (PSIRT) became aware of the issue in June, following a report from Mandiant. The team provided indicators of compromise (IOCs), advising administrators to monitor `/var/log/scripts.log` for attempts to upload tenant configuration data to vSmart controllers. Cisco recommends generating an admin-tech file for review to assist in assessing potential compromise. While patches for CVE-2026-20245 are not yet available, Cisco advises upgrading to the software fixed for CVE-2026-20182 on May 14th.
This incident is part of a larger trend of Cisco vulnerabilities being exploited in the wild, with CISA having flagged 90 Cisco vulnerabilities for abuse over the past several years. Notably, four of these vulnerabilities were within the SD-WAN Manager, and six were exploited by ransomware operations.