Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Cisco has issued a warning about a high-severity, unpatched zero-day vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager, which is actively being exploited to achieve root privilege escalation.
Intelligence analysis by Gemini 2.5 Flash

A critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager allows local attackers with low privileges to execute arbitrary commands as root by uploading a crafted file. Cisco is aware of limited exploitation cases and is working on patches, while advising customers to secure against related flaws.
Imagine a special computer program that helps manage all the internet connections for big companies, like a super-smart traffic cop for data. Bad guys found a secret trick, like a hidden key, that lets them sneak into this traffic cop program and tell it what to do, even though they aren't supposed to. Cisco, the company that made the program, is warning everyone about this hidden key so they can try to fix it before too many bad guys use it to cause trouble.
Analysis
Cisco has alerted users to a high-severity zero-day vulnerability, tracked as CVE-2026-20245, affecting its Catalyst SD-WAN Manager. This flaw is currently being exploited in the wild, allowing attackers to escalate privileges to root level. The vulnerability, which stems from insufficient validation of user-supplied input, enables local attackers with low privileges to execute arbitrary commands as the root user. Attackers can exploit this by uploading a specially crafted file to the affected system.
Exploitation Details
To successfully exploit this vulnerability, an attacker typically requires netadmin privileges on the system. This means they would need valid credentials or to exploit other vulnerabilities such as CVE-2026-20182 or CVE-2026-20127 to gain initial access. Cisco has observed limited instances where this bug has led to configuration changes being pushed to edge devices. Mandiant, a Google Cloud cybersecurity subsidiary, reported the exploitation of CVE-2026-20245 to Cisco's Product Security Incident Response Team (PSIRT) in June.
Indicators of Compromise and Remediation
While no specific details about the attacks were shared, Mandiant provided indicators of compromise (IOCs). Administrators are advised to inspect their SD-WAN /var/log/scripts.log file for suspicious attempts to upload tenant configuration data to vSmart controllers, aiming to escalate privileges through legitimate commands. Cisco recommends customers open a case with the Cisco TAC for assistance in determining if their Catalyst SD-WAN Manager has been compromised, suggesting they first generate an admin-tech file to aid in the review process.
Related Vulnerabilities
Cisco has been actively addressing several other critical vulnerabilities in its SD-WAN products. Last month, a maximum severity Catalyst SD-WAN Controller authentication bypass flaw (CVE-2026-20182) was also tagged as actively exploited, allowing administrative privileges on unpatched devices. Although patches for CVE-2026-20245 are not yet available, Cisco has urged customers to upgrade to the software versions fixed for CVE-2026-20182, which were released on May 14. In February, Cisco patched another Catalyst SD-WAN Manager information disclosure flaw (CVE-2026-20133), which CISA later flagged as exploited. Two more flaws (CVE-2026-20128 and CVE-2026-20122) were also reported as being abused in the wild in February. In March, a critical authentication-bypass vulnerability (CVE-2026-20127) was addressed, which had been exploited in zero-day attacks since at least 2023.
Key points
- Cisco has warned about an actively exploited zero-day vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager.
- The flaw allows local attackers with low privileges to achieve root privilege escalation via command injection.
- Exploitation requires netadmin privileges or prior exploitation of other vulnerabilities (CVE-2026-20182 or CVE-2026-20127).
- No patches are currently available for CVE-2026-20245, but Cisco advises upgrading to software versions that fix a related flaw, CVE-2026-20182.
- Mandiant reported the exploitation, and indicators of compromise (IOCs) are available for administrators to check their systems.
Despite active exploitation, the prompt disclosure by Cisco and the involvement of Mandiant should accelerate the development and release of security patches. This transparency allows affected organizations to take immediate steps to mitigate risks by applying recommended workarounds and monitoring for indicators of compromise, ultimately strengthening their security posture against future attacks.
The ongoing exploitation of an unpatched zero-day flaw in Cisco SD-WAN Manager suggests a significant window of vulnerability for many organizations. Without immediate patches, attackers could continue to exploit this weakness, potentially leading to widespread root privilege escalation and unauthorized access to critical network infrastructure, further complicating remediation efforts.



