Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) – Help Net Security

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-06-05 08:44:00

A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers.

“To exploit this vulnerability, an attacker must have netadmin privileges on an affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods,” the company shared on Thursday.

It also said that it has observed “limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.”

About CVE-2026-20245

CVE-2026-20245, which affects the command-line interface of Cisco Catalyst SD-WAN Manager, stems from insufficient validation of user-supplied input.

Authenticated, local attackers can exploit it by uploading a crafted file to the affected system, and they can consequently execute arbitrary commands as root.

As noted above, attackers must first gain authenticated…