Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

By Abinaya
Publication Date: 2026-06-05 06:30:00

Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges.

The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and stems from improper input validation in the system’s command-line interface.

According to Cisco’s advisory, the flaw stems from insufficient sanitization of user-supplied input during the processing of uploaded files.

An authenticated attacker can exploit this weakness by uploading a specially crafted file, which triggers command injection and enables privilege escalation to the root user.

Once root access is obtained, attackers can fully compromise the SD-WAN management plane, manipulate configurations, and potentially impact connected edge devices. The attack requires netadmin-level privileges, meaning the threat is not directly exploitable by unauthenticated actors.

Cisco SD-WAN Vulnerability…