Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execute arbitrary commands as root. Currently, there are no patches available, and Cisco is advising customers to upgrade their SD-WAN software to address related vulnerabilities.
The Cisco Catalyst SD-WAN Manager is experiencing an active exploitation campaign due to a critical vulnerability (CVE-2026-20245) with a CVSS score of 7.8. This vulnerability, caused by a lack of proper input validation, allows an authenticated, local attacker to gain root privileges on the system by uploading a specially crafted file. The vulnerability affects deployments including On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). Initial investigations by Google Mandiant researchers identified the exploitation leading to configuration changes on edge devices. The threat actors behind the exploitation are currently unknown, but a threat activity cluster (UAT-8616) has been linked to the abuse of a related vulnerability (CVE-2026-20127) dating back to 2023. Cisco is urging customers to upgrade their SD-WAN software to address the underlying vulnerabilities, specifically CVE-2026-20182, which was patched in May 2026.
