Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco says a high-severity Catalyst SD-WAN Manager flaw is being actively exploited, with no direct patch or mitigation yet available.
Intelligence analysis by GPT-5.4 Mini

Cisco warned that CVE-2026-20245 in Catalyst SD-WAN Manager is under active exploitation and can let an authenticated local attacker run commands as root by uploading a crafted file. Cisco says there is no patch or mitigation yet, and advises checking logs for signs of abuse.
Cisco found a bad hole in its SD-WAN manager software that can let an intruder take over like a houseguest stealing the master key. There is no direct fix yet, so defenders have to look for signs someone already slipped in.
Analysis
What Cisco disclosed
Cisco says CVE-2026-20245 affects Catalyst SD-WAN Manager, formerly SD-WAN vManage, across on-prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud, and SD-WAN for Government deployments. The flaw is rated 7.8 on the CVSS scale and stems from insufficient validation of user-supplied input in the CLI.
According to Cisco, an attacker with netadmin privileges can upload a crafted file and trigger command injection that leads to arbitrary commands running as root. Cisco notes that reaching that privilege level would require valid credentials or abuse of CVE-2026-20182 or CVE-2026-20127, both of which have been exploited in the wild as zero-days.
What Cisco observed
Cisco said it has seen limited cases where exploitation of CVE-2026-20245 led to a configuration change being pushed to edge devices. The company credited Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan with discovering and reporting the issue, but said it does not know who is behind the current exploitation.
What defenders can do now
Cisco says there are currently no patches or mitigations specifically for CVE-2026-20245. Customers are told to upgrade to SD-WAN software that includes the fixes released for CVE-2026-20182 on May 14, 2026. Cisco also recommends checking /var/log/scripts.log for suspicious file-upload activity, including entries that reference uploaded CSV files or tenant, serial number, and chassis-number scripts.
The disclosure adds to a run of Cisco SD-WAN issues that have already been marked as actively exploited this year, making this latest flaw part of a broader pattern rather than an isolated case.
Key points
- Cisco says CVE-2026-20245 in Catalyst SD-WAN Manager is being actively exploited.
- The flaw can let an authenticated local attacker execute commands as root after uploading a crafted file.
- Cisco says the issue affects several SD-WAN deployment types, including on-prem and cloud-managed options.
- There are no patches or mitigations specifically for CVE-2026-20245 yet.
- Cisco advises upgrading to software that includes the May 14, 2026 fixes for CVE-2026-20182 and checking logs for suspicious script activity.
Cisco says customers can reduce risk by upgrading to software that includes the fixes released for CVE-2026-20182. The company also provided log locations and example indicators that can help defenders spot suspicious activity early.
There is no direct patch or mitigation for CVE-2026-20245 right now, which leaves exposed systems relying on detection and indirect hardening. Cisco also warned that internet-exposed systems are at heightened risk, and it has already seen cases where exploitation affected edge-device configuration.



