The images in this article were generated with artificial intelligence. How we publish
Cisco has warned that a high severity vulnerability in Catalyst SD-WAN Manager, registered as CVE-2026-20245 and with a CVSS score of 7.8, it is being actively exploited. The failure affects On-Prem deployments, Cisco SD-WAN Cloud (including Cisco-managed service) and the government variant (FedRAMP). According to the company, the root of the problem is a insufficient validation of data entered by the user in the CLI interface, which allows an authenticated attacker with local privileges to run arbitrary commands like root by uploading a malformed file.
From a technical point of view, the exploitation is not completely "remote" on its own: it requires the attacker to have netadmin privileges, which involves valid credentials or the prior exploitation of authentication default vulnerabilities in the same component, specifically CVE-2026-20182 and CVE-2026-20127. The latter have been described as high-impact authentication bypass and have already been used in actual attacks; in fact, researchers have linked the abuse of CVE-2026-20127 to a group with continued activity since 2023. Cisco has reported limited cases where CVE-2026-20245 was translated into configuration changes spread to edge devices, demonstrating the potential for persistence and damage in network infrastructure.

The context is worrying: CVE-2026-20245 is, according to the notice, the seventh vulnerability of SD-WAN from Cisco reported as exploited in what goes on in the year, a pattern that shows how attack chains combine authentication bypasss and local vulnerabilities to climb privileges up root. The discoverers who reported this new failure are researchers of Google Mandiant, and Cisco points out that for now the actor behind the farms is not clearly known.
The implications for organizations using Cisco SD-WAN are clear: a compromised administrative access can allow for configuration modifications, insertion of malicious routes, traffic interception and starting point for lateral movement or deployment of malicious loads in branches. Internet-exposed systems have a high risk of commitment they must be treated with priority.

As for specific mitigation and actions, the first thing to accept is that there is not yet a specific patch for CVE-2026-20245 at the time of notice; therefore, measures should focus on reducing the attack surface and cutting the operating chains that would allow its use. Apply the updates and patches already available that Cisco published to correct CVE-2026-20182 (May 14, 2026) and other related corrections; check that your SD-WAN versions include those fixes. It then restricts and audits administrative access: remove direct Internet exposure from management panels, limit netadmin access to reliable IP ranges, apply multifactor authentication where possible and rotate administrative credentials. If you have perimeter firewalls or WAF / NGFW, create temporary rules to block access to management interfaces until additional patches are available.
For detection and response, Cisco recommends looking for compromise indicators in the log file / var / log / scripts.log where there may be records of suspicious charges or executions. In addition, search for configurations and for changes applied to edge devices that may indicate unauthorized modifications. Activate network detection for unusual control and management patterns, review the inventory of accounts with netadmin privileges, and if you identify abnormal activity, isolate the affected node, preserve logs for forensic analysis and contact Cisco TAC and its incident response team. If you need references on exploited vulnerabilities and government recommendations for priority, see the catalogue of exploited vulnerabilities of CISA at https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog and NVD inputs for technical monitoring of CVE in https: / / nvd.nist.gov /.
Finally, take an in-depth defense position: Segment the administrative network, monitor the integrity of configurations, maintain secure copies of critical configurations and test incident response plans that contemplate the temporary loss of control of SD-WAN platform. These measures do not replace a patch, but significantly reduce the probability of successful exploitation and address the impact if it occurs.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...