SECURITYTHE REGISTER
Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
Cisco's SD-WAN management software is under attack due to a high-severity zero-day vulnerability (CVE-2026-20245), which allows authenticated attackers to escalate privileges and execute commands. Cisco has not yet released a patch, and this is the sixth SD-WAN vulnerability exploited since the year began.
Mentioned
Related Signal
Adjacent reporting
- Cisco zero-day under ongoing attack by persistent threat group
- Adobe Patches Actively Exploited Zero-Day That Lingered for Months
- Ivanti customers confront yet another actively exploited zero-day
- Fortinet Issues Emergency Patch for FortiClient Zero-Day
- Microsoft warns of new Defender zero-days exploited in attacks
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks