Cisco Catalyst SD-WAN Manager hit by 7th actively-exploited zero-day of 2026 with no patch available
Cisco $CSCO confirmed attackers are exploiting an unpatched flaw in its Catalyst SD-WAN Manager, the software that controls entire corporate and government networks. Tracked as CVE-2026-20245, it lets an attacker with admin access run commands as root and was discovered by Google
Cisco $CSCO is warning that attackers are actively exploiting CVE-2026-20245, a flaw in Catalyst SD-WAN Manager, with no patch or workaround available at disclosure. An attacker who already holds admin-level access can upload a crafted file and run commands as root, taking full control. Cisco has observed exploitation in limited cases, including pushes of configuration changes to edge devices. Google Mandiant discovered and reported the bug. It affects every deployment type, from on-premise to Cisco-managed cloud and federal government environments, and is the seventh Cisco SD-WAN zero-day flagged as actively exploited in 2026.