The images in this article were generated with artificial intelligence. How we publish
Cisco has warned that a high severity vulnerability in Catalyst SD-WAN Manager, registered as CVE-2026-20245 and with a CVSS score of 7.8, it is being actively exploited. The failure affects On-Prem deployments, Cisco SD-WAN Cloud (including Cisco-managed service) and the government variant (FedRAMP). According to the company, the root of the problem is a insufficient validation of data entered by the user in the CLI interface, which allows an authenticated attacker with local privileges to run arbitrary commands like root by uploading a malformed file.
From a technical point of view, the exploitation is not completely "remote" on its own: it requires the attacker to have netadmin privileges, which involves valid credentials or the prior exploitation of authentication default vulnerabilities in the same component, specifically CVE-2026-20182 and CVE-2026-20127. The latter have been described as high-impact authentication bypass and have already been used in actual attacks; in fact, researchers have linked the abuse of CVE-2026-20127 to a group with continued activity since 2023. Cisco has reported limited cases where CVE-2026-20245 was translated into configuration changes spread to edge devices, demonstrating the potential for persistence and damage in network infrastructure.

The context is worrying: CVE-2026-20245 is, according to the notice, the seventh vulnerability of SD-WAN from Cisco reported as exploited in what goes on in the year, a pattern that shows how attack chains combine authentication bypasss and local vulnerabilities to climb privileges up root. The discoverers who reported this new failure are researchers of Google Mandiant, and Cisco points out that for now the actor behind the farms is not clearly known.
The implications for organizations using Cisco SD-WAN are clear: a compromised administrative access can allow for configuration modifications, insertion of malicious routes, traffic interception and starting point for lateral movement or deployment of malicious loads in branches. Internet-exposed systems have a high risk of commitment they must be treated with priority.

As for specific mitigation and actions, the first thing to accept is that there is not yet a specific patch for CVE-2026-20245 at the time of notice; therefore, measures should focus on reducing the attack surface and cutting the operating chains that would allow its use. Apply the updates and patches already available that Cisco published to correct CVE-2026-20182 (May 14, 2026) and other related corrections; check that your SD-WAN versions include those fixes. It then restricts and audits administrative access: remove direct Internet exposure from management panels, limit netadmin access to reliable IP ranges, apply multifactor authentication where possible and rotate administrative credentials. If you have perimeter firewalls or WAF / NGFW, create temporary rules to block access to management interfaces until additional patches are available.
For detection and response, Cisco recommends looking for compromise indicators in the log file / var / log / scripts.log where there may be records of suspicious charges or executions. In addition, search for configurations and for changes applied to edge devices that may indicate unauthorized modifications. Activate network detection for unusual control and management patterns, review the inventory of accounts with netadmin privileges, and if you identify abnormal activity, isolate the affected node, preserve logs for forensic analysis and contact Cisco TAC and its incident response team. If you need references on exploited vulnerabilities and government recommendations for priority, see the catalogue of exploited vulnerabilities of CISA at https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog and NVD inputs for technical monitoring of CVE in https: / / nvd.nist.gov /.
Finally, take an in-depth defense position: Segment the administrative network, monitor the integrity of configurations, maintain secure copies of critical configurations and test incident response plans that contemplate the temporary loss of control of SD-WAN platform. These measures do not replace a patch, but significantly reduce the probability of successful exploitation and address the impact if it occurs.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...