Cisco discloses seventh 2026 SD-WAN zero-day CVE-2026-20245, root command injection, no patch yet
No patch and no workaround yet: Cisco $CSCO confirmed a root-level command injection flaw in its Catalyst SD-WAN Manager, CVE-2026-20245, that attackers are already exploiting. It is the seventh SD-WAN zero-day Cisco has flagged as exploited in 2026. Reported by Mandiant. Source:
Cisco $CSCO has disclosed the seventh SD-WAN product vulnerability confirmed as exploited in the wild this year, and unlike the earlier cases it has no patch and no workaround available. The flaw, tracked as CVE-2026-20245, sits in the command-line interface of Cisco Catalyst SD-WAN Manager, the central platform many enterprises and carriers use to operate their software-defined wide-area networks. According to Cisco's security advisory, an attacker who already holds netadmin privileges can upload a specially crafted file that triggers command injection and grants root access to the system. Those privileges can be obtained through stolen credentials or by chaining earlier SD-WAN flaws such as CVE-2026-20182 and CVE-2026-20127. Cisco says it has observed limited cases where exploitation resulted in a configuration change being pushed out to edge devices. The vulnerability was reported by Mandiant, and Cisco product security learned of active exploitation in June. With a fix only expected in a future Catalyst SD-WAN Manager release, Cisco has published indicators of compromise so defenders can hunt for signs of intrusion. Source: Cisco security advisory.