CVE-2026-20245
Coverage of CVE-2026-20245 in the Nexus archive.
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
A high-severity security flaw in Cisco Catalyst SD-WAN, tracked as CVE-2026-20245, was exploited by an unknown threat actor as a zero-day for at least two months before public disclosure. Mandiant found the vulnerability allows an authenticated, local attacker to execute arbitrary commands with elevated privileges.
- Cisco SD-WAN make-me-root bug under attack
Cisco issued a fix for a critical vulnerability (CVE-2026-20262) in its Catalyst SD-WAN Manager, which attackers are actively exploiting to gain root privileges. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch within two weeks. The vulnerability arises from improper input validation during file uploads, requiring valid credentials for exploitation.
- Cisco customers encounter another SD-WAN zero-day under attack
Cisco customers are facing another actively exploited zero-day vulnerability (CVE-2026-20245) in its SD-WAN management software, marking the seventh such exploit this year. The flaw allows authenticated attackers to execute commands as root, but Cisco warns no patch or workaround is currently available, and exploitation requires existing credentials or prior vulnerabilities.
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has issued a warning about a high-severity security flaw (CVE-2026-20245) in its Catalyst SD-WAN Manager, which is being actively exploited. The vulnerability, with a CVSS score of 7.8, affects multiple deployment types including On-Prem, Cloud-Pro, Cloud (Cisco Managed), and SD-WAN for Government (FedRAMP). No patch is currently available.
- Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
Cisco's SD-WAN management software is under attack due to a high-severity zero-day vulnerability (CVE-2026-20245), which allows authenticated attackers to escalate privileges and execute commands. Cisco has not yet released a patch, and this is the sixth SD-WAN vulnerability exploited since the year began.
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Cisco warned of a high-severity unpatched zero-day vulnerability in its Cisco Catalyst SD-WAN Manager (CVE-2026-20245) that is currently being exploited in attacks to enable root privilege escalation.