Back to Blog
Cybersecurity June 7, 2026 5 min read

Cisco's 7th SD-WAN Zero-Day of 2026: CVE-2026-20245 Enables Root Execution — No Patch Available

Cisco disclosed CVE-2026-20245 on June 5, a privilege escalation flaw in Catalyst SD-WAN Manager that lets an authenticated attacker execute arbitrary commands as root. It is the seventh actively exploited SD-WAN zero-day in 2026, and no patch exists yet.

Cisco's 7th SD-WAN Zero-Day of 2026: CVE-2026-20245 Enables Root Execution — No Patch Available

Cisco disclosed CVE-2026-20245 on June 5, 2026 — the seventh actively exploited zero-day targeting Catalyst SD-WAN Manager this year. No patch is available, no workaround exists, and active exploitation has already been observed in the wild.

CVE: CVE-2026-20245 | Product: Cisco Catalyst SD-WAN Manager | Impact: Root command execution | Patch: None

What the Vulnerability Does

The flaw lives in the CLI of Cisco Catalyst SD-WAN Manager. It stems from insufficient input validation: an authenticated attacker with netadmin privileges can upload a crafted file to execute arbitrary commands as root on the underlying system. Every deployment type is affected — on-premises, Cloud-Pro, Cisco-managed cloud, and FedRAMP Government.

Cisco confirmed limited successful exploitation in the wild, with at least some incidents resulting in configuration changes being pushed to edge devices from compromised controllers. That’s a particularly severe impact: a single compromised SD-WAN Manager can modify the configuration of every branch site it manages.

The Chain Attack

CVE-2026-20245 is typically the second step in an attack chain. Threat actors first exploit CVE-2026-20182 or CVE-2026-20127 (both previously disclosed and patched) to obtain netadmin credentials, then pivot to CVE-2026-20245 for root. If your SD-WAN Manager was exposed to those earlier vulnerabilities and you didn’t confirm clean remediation, assume it may already be compromised before applying any future patch.

Cisco’s advisory is explicit on this point: applying the upcoming software update alone will not resolve the vulnerability on compromised systems. If intrusion is suspected, collect admin-tech logs before upgrading and contact Cisco TAC.

What to Do Now

No patch has shipped. Cisco says a fix will be included in a future Catalyst SD-WAN Manager release with no date given. Until then:

  • Restrict management-plane access: firewall SD-WAN Manager’s management interface off from any untrusted or internet-facing network immediately.
  • Rotate netadmin credentials: all accounts with netadmin or higher privileges should be rotated now, not after the patch.
  • Audit edge device configurations: look for unauthorized configuration changes pushed to branch sites in the last 30–60 days.
  • Monitor for CLI file uploads: alert on unexpected file uploads to the SD-WAN Manager CLI interface.

Seven Zero-Days in One Year

The pattern here is as notable as the individual vulnerability. Seven actively exploited zero-days in Cisco SD-WAN Manager in a single calendar year suggests a sustained and well-resourced campaign against Cisco’s network management infrastructure. This is not opportunistic scanning — it is targeted exploitation of a specific product by threat actors who understand its architecture.

If your organization runs Catalyst SD-WAN and the management interface has any external exposure, treat that exposure as an active breach until you can confirm otherwise.

Sources

Cisco CVE-2026-20245 zero-day SD-WAN