Cisco says attackers are exploiting a new zero-day in Catalyst SD-WAN Manager, and affected organizations do not yet have a patch. The flaw, CVE-2026-20245, is a command-injection vulnerability in the command-line interface that lets an authenticated local attacker with netadmin privileges execute arbitrary commands as root by uploading a crafted file. Cisco said exploitation has been limited but observed cases where attackers pushed configuration changes to edge devices, and published indicators of compromise.
Eduard Kovacs
2026.06.25
96% relevant
This is a direct update on the same underlying event: exploitation of Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245. The new source adds that Mandiant observed exploitation as early as March 2026 at a service provider, describes use of SSH access via the default vmanage-admin account, privilege escalation to root, password changes for stealth, cleanup steps, and possible links to earlier SD-WAN zero-days CVE-2026-20127 or CVE-2026-20182.
2026.06.24
88% relevant
This source adds specific incident details to the same CVE-2026-20245 story, including Mandiant's report that exploitation began earlier than Cisco initially disclosed and that an attacker at a communications service provider escalated from a compromised admin account to root and exfiltrated SD-WAN fabric configurations.
Lawrence Abrams
2026.06.24
96% relevant
This article updates the same underlying event by detailing Mandiant's incident findings on CVE-2026-20245 exploitation, including use of rogue peering, the vmanage-admin account, the tenant-upload CSV payload, creation of a temporary root account named 'troot,' and anti-forensic cleanup. It also ties the intrusion path to previously disclosed Cisco SD-WAN authentication-bypass flaws CVE-2026-20127 and CVE-2026-20182.
2026.06.17
28% relevant
The article mentions CVE-2026-20245 only as background and is not primarily about that later zero-day, so it is related product context rather than the same underlying event.
info@thehackernews.com (The Hacker News)
2026.06.10
92% relevant
This source updates the same Cisco event by saying CISA added CVE-2026-20245 to KEV amid active exploitation, which strengthens the operational urgency for organizations running Catalyst SD-WAN Manager while waiting for a vendor fix and applying available mitigations.
info@thehackernews.com (The Hacker News)
2026.06.06
99% relevant
This article covers the same underlying event: Cisco's disclosure that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited in the wild and currently lacks an available fix.
2026.06.05
98% relevant
This article is a direct report on the same event: Cisco's disclosure that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited in the wild with no patch available. It adds reporting detail that exploitation appears to date back at least a week, that all versions and deployment types including FedRAMP are affected, and that Cisco says attackers would need netadmin access or exploitation of CVE-2026-20182 or CVE-2026-20127.
Sergiu Gatlan
2026.06.05
99% relevant
This article covers the same underlying event: Cisco's warning that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited as a zero-day with no patch available. It adds concrete details on the privilege-escalation path, affected deployment types, Mandiant's role in reporting, the dependency on valid netadmin access or exploitation of CVE-2026-20182/CVE-2026-20127, observed configuration changes pushed to edge devices, and example indicators of compromise in scripts.log.
Eduard Kovacs
2026.06.05
100% relevant
This article establishes a distinct new event: Cisco's disclosure of in-the-wild exploitation of CVE-2026-20245 in Catalyst SD-WAN Manager, a separate zero-day from the other Cisco and SD-WAN stories already tracked.