Cisco SD-WAN under attack: active exploitation of CVE-2026-20245 that allows to climb root by uploading malformed files

Author: Published 4 min de lectura 162 reading

The images in this article were generated with artificial intelligence. How we publish

Cisco has warned that a high severity vulnerability in Catalyst SD-WAN Manager, registered as CVE-2026-20245 and with a CVSS score of 7.8, it is being actively exploited. The failure affects On-Prem deployments, Cisco SD-WAN Cloud (including Cisco-managed service) and the government variant (FedRAMP). According to the company, the root of the problem is a insufficient validation of data entered by the user in the CLI interface, which allows an authenticated attacker with local privileges to run arbitrary commands like root by uploading a malformed file.

From a technical point of view, the exploitation is not completely "remote" on its own: it requires the attacker to have netadmin privileges, which involves valid credentials or the prior exploitation of authentication default vulnerabilities in the same component, specifically CVE-2026-20182 and CVE-2026-20127. The latter have been described as high-impact authentication bypass and have already been used in actual attacks; in fact, researchers have linked the abuse of CVE-2026-20127 to a group with continued activity since 2023. Cisco has reported limited cases where CVE-2026-20245 was translated into configuration changes spread to edge devices, demonstrating the potential for persistence and damage in network infrastructure.

Cisco SD-WAN under attack: active exploitation of CVE-2026-20245 that allows to climb root by uploading malformed files
Image generated with IA.

The context is worrying: CVE-2026-20245 is, according to the notice, the seventh vulnerability of SD-WAN from Cisco reported as exploited in what goes on in the year, a pattern that shows how attack chains combine authentication bypasss and local vulnerabilities to climb privileges up root. The discoverers who reported this new failure are researchers of Google Mandiant, and Cisco points out that for now the actor behind the farms is not clearly known.

The implications for organizations using Cisco SD-WAN are clear: a compromised administrative access can allow for configuration modifications, insertion of malicious routes, traffic interception and starting point for lateral movement or deployment of malicious loads in branches. Internet-exposed systems have a high risk of commitment they must be treated with priority.

Cisco SD-WAN under attack: active exploitation of CVE-2026-20245 that allows to climb root by uploading malformed files
Image generated with IA.

As for specific mitigation and actions, the first thing to accept is that there is not yet a specific patch for CVE-2026-20245 at the time of notice; therefore, measures should focus on reducing the attack surface and cutting the operating chains that would allow its use. Apply the updates and patches already available that Cisco published to correct CVE-2026-20182 (May 14, 2026) and other related corrections; check that your SD-WAN versions include those fixes. It then restricts and audits administrative access: remove direct Internet exposure from management panels, limit netadmin access to reliable IP ranges, apply multifactor authentication where possible and rotate administrative credentials. If you have perimeter firewalls or WAF / NGFW, create temporary rules to block access to management interfaces until additional patches are available.

For detection and response, Cisco recommends looking for compromise indicators in the log file / var / log / scripts.log where there may be records of suspicious charges or executions. In addition, search for configurations and for changes applied to edge devices that may indicate unauthorized modifications. Activate network detection for unusual control and management patterns, review the inventory of accounts with netadmin privileges, and if you identify abnormal activity, isolate the affected node, preserve logs for forensic analysis and contact Cisco TAC and its incident response team. If you need references on exploited vulnerabilities and government recommendations for priority, see the catalogue of exploited vulnerabilities of CISA at https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog and NVD inputs for technical monitoring of CVE in https: / / nvd.nist.gov /.

Finally, take an in-depth defense position: Segment the administrative network, monitor the integrity of configurations, maintain secure copies of critical configurations and test incident response plans that contemplate the temporary loss of control of SD-WAN platform. These measures do not replace a patch, but significantly reduce the probability of successful exploitation and address the impact if it occurs.

Coverage

Related

More news on the same subject.