discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Cisco has issued a warning about a high-severity, unpatched zero-day vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager, which is actively being exploited to achieve root privilege escalation.

By Sergiu Gatlan·Jun 5·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Image: bleepingcomputer.com

A critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager allows local attackers with low privileges to execute arbitrary commands as root by uploading a crafted file. Cisco is aware of limited exploitation cases and is working on patches, while advising customers to secure against related flaws.

Why it matters

This story matters to security professionals as it highlights an actively exploited zero-day in widely used network management software, posing a significant risk of root privilege escalation and potential system compromise for organizations relying on Cisco SD-WAN.

Imagine a special computer program that helps manage all the internet connections for big companies, like a super-smart traffic cop for data. Bad guys found a secret trick, like a hidden key, that lets them sneak into this traffic cop program and tell it what to do, even though they aren't supposed to. Cisco, the company that made the program, is warning everyone about this hidden key so they can try to fix it before too many bad guys use it to cause trouble.

Analysis

Cisco has alerted users to a high-severity zero-day vulnerability, tracked as CVE-2026-20245, affecting its Catalyst SD-WAN Manager. This flaw is currently being exploited in the wild, allowing attackers to escalate privileges to root level. The vulnerability, which stems from insufficient validation of user-supplied input, enables local attackers with low privileges to execute arbitrary commands as the root user. Attackers can exploit this by uploading a specially crafted file to the affected system.

Exploitation Details

To successfully exploit this vulnerability, an attacker typically requires netadmin privileges on the system. This means they would need valid credentials or to exploit other vulnerabilities such as CVE-2026-20182 or CVE-2026-20127 to gain initial access. Cisco has observed limited instances where this bug has led to configuration changes being pushed to edge devices. Mandiant, a Google Cloud cybersecurity subsidiary, reported the exploitation of CVE-2026-20245 to Cisco's Product Security Incident Response Team (PSIRT) in June.

Indicators of Compromise and Remediation

While no specific details about the attacks were shared, Mandiant provided indicators of compromise (IOCs). Administrators are advised to inspect their SD-WAN /var/log/scripts.log file for suspicious attempts to upload tenant configuration data to vSmart controllers, aiming to escalate privileges through legitimate commands. Cisco recommends customers open a case with the Cisco TAC for assistance in determining if their Catalyst SD-WAN Manager has been compromised, suggesting they first generate an admin-tech file to aid in the review process.

Related Vulnerabilities

Cisco has been actively addressing several other critical vulnerabilities in its SD-WAN products. Last month, a maximum severity Catalyst SD-WAN Controller authentication bypass flaw (CVE-2026-20182) was also tagged as actively exploited, allowing administrative privileges on unpatched devices. Although patches for CVE-2026-20245 are not yet available, Cisco has urged customers to upgrade to the software versions fixed for CVE-2026-20182, which were released on May 14. In February, Cisco patched another Catalyst SD-WAN Manager information disclosure flaw (CVE-2026-20133), which CISA later flagged as exploited. Two more flaws (CVE-2026-20128 and CVE-2026-20122) were also reported as being abused in the wild in February. In March, a critical authentication-bypass vulnerability (CVE-2026-20127) was addressed, which had been exploited in zero-day attacks since at least 2023.

Key points

  • Cisco has warned about an actively exploited zero-day vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager.
  • The flaw allows local attackers with low privileges to achieve root privilege escalation via command injection.
  • Exploitation requires netadmin privileges or prior exploitation of other vulnerabilities (CVE-2026-20182 or CVE-2026-20127).
  • No patches are currently available for CVE-2026-20245, but Cisco advises upgrading to software versions that fix a related flaw, CVE-2026-20182.
  • Mandiant reported the exploitation, and indicators of compromise (IOCs) are available for administrators to check their systems.
The Upside

Despite active exploitation, the prompt disclosure by Cisco and the involvement of Mandiant should accelerate the development and release of security patches. This transparency allows affected organizations to take immediate steps to mitigate risks by applying recommended workarounds and monitoring for indicators of compromise, ultimately strengthening their security posture against future attacks.

The Downside

The ongoing exploitation of an unpatched zero-day flaw in Cisco SD-WAN Manager suggests a significant window of vulnerability for many organizations. Without immediate patches, attackers could continue to exploit this weakness, potentially leading to widespread root privilege escalation and unauthorized access to critical network infrastructure, further complicating remediation efforts.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityzero-dayciscosd-wanvulnerabilityprivilege-escalation

Author

Sergiu Gatlan

Intelligence analysis by

Gemini 2.5 Flash

Published

Jun 5, 2026

Source

bleepingcomputer.com

Share

Topics

securityzero-dayciscosd-wanvulnerabilityprivilege-escalation

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…