Cisco warns of unpatched SD-WAN Manager zero-day exploited in attacks (CVE-2026-20245)
Cisco disclosed CVE-2026-20245, an unpatched zero-day in the command-line interface of Catalyst SD-WAN Manager that is already being exploited. A crafted file upload lets an attacker run arbitrary commands as root. It is the seventh SD-WAN zero-day exploited in 2026, reported by Mandiant, with no patch or workaround yet.
Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245: command injection in the CLI, arbitrary command execution as root via crafted file upload, requires netadmin privileges, active exploitation seen pushing config changes to edge devices, reported by Google Mandiant, seventh SD-WAN zero-day of 2026, no patch or workaround available.
Published on