CVE-2026-20245

Published Jun 4, 2026

Last updated a month ago

Exploit knownCVSS high 7.8
Network
Tunneling protocol
Server
Firmware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20245 is a command injection vulnerability found in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage. This flaw arises from insufficient validation of user-supplied input, allowing an authenticated attacker with netadmin privileges to upload a specially crafted file. Upon successful exploitation, the attacker can execute arbitrary commands as root on the affected system. Cisco has observed limited instances of this vulnerability being exploited in the wild, with some cases resulting in configuration changes being pushed to edge devices. It is noted that the required netadmin privileges can be obtained either through valid credentials or by leveraging other vulnerabilities, such as CVE-2026-20182 or CVE-2026-20127.

Description
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.  To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
Source
psirt@cisco.com
NVD status
Analyzed
Products
catalyst_sd-wan_manager, sd-wan_vsmart_controller

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Exploit added on
Jun 9, 2026
Exploit action due
Jun 23, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@cisco.com
CWE-116

Social media

Hype score
Not currently trending
  1. CVE-2026-20245. 0day Intel: 🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-20245 PT ID: PT-

    @lyrie_ai

    11 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-20245. CVE-2026-20245 added to CISA KEV: Cisco Catalyst SD-WAN Manager

    @lyrie_ai

    6 Jul 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. ⚠️ ثغرة حرجة في كاتاليست إس دي-وان تُستغل كصفر-يوم وتمنح المهاجم تنفيذ أوامر بصلاحيات الجذر. المعرّف : CVE-2026-20245 الخطورة : 7.8 (CVSS) - High المتأثر : Cisco Catalyst SD-WAN

    @KasperskyDev

    4 Jul 2026

    60 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Recent zero-day exploits like CVE-2026-20245 (Cisco SD-WAN) & CVE-2025-67038 (Lantronix EDS5000) show active network device targeting. These vulnerabilities threaten data privacy & integrity in transit via interception & command execution. #Cybersecurity #NetworkSecur

    @YourAnon_irc

    29 Jun 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Cisco-Catalyst-SD-WAN-Manager(広域ネットワークをソフトウェアで一元管理するコントローラ)に対するゼロデイ攻撃が報告されています。CVE-2026-20245を悪用してルート権限を奪取する手口で、サービスプロバイダの

    @MalwareBibleJP

    28 Jun 2026

    1505 Impressions

    4 Retweets

    18 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  6. Recent findings reveal encrypted DNS (TLS/QUIC) still exposes critical metadata, impacting data privacy in transit. Also, active exploits target Cisco SD-WAN zero-day (CVE-2026-20245) & Lantronix EDS5000 (CVE-2025-67038). Stay vigilant! #Cybersecurity #InfoSec #ZeroDay

    @YourAnon_irc

    28 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Critical flaws emerge: Cisco CUCM (CVE-2026-20230) & SD-WAN (CVE-2026-20245) zero-days exploited for root access. Also, LiteLLM AI gateway RCE (CVE-2026-42271) under active attack. Data privacy & integrity in transit are at grave risk. Patch ASAP! #Cybersecurity #ZeroDay

    @YourAnon_irc

    27 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2026-20245 zero-day in Cisco Catalyst SD-WAN Manager exploited to escalate from admin to root, with deliberate anti-forensic cleanup designed to leave responders empty-handed. Key findings: - The vulnerability lives in the tenant file upload feature of the SD-WAN Manager ht

    @DFIR_Radar

    27 Jun 2026

    104 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Critical Cisco SD-WAN zero-day (CVE-2026-20245) and CUCM flaw (CVE-2026-20230) exploited for root access. Threats to data privacy & integrity in transit are severe. Patch immediately! #Cybersecurity #ZeroDay #InfoSec

    @YourAnon_irc

    26 Jun 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2026-20245 zero-day in Cisco Catalyst SD-WAN Manager exploited in the wild: attackers escalated from admin SSH to root via malicious CSV upload, then ran a cleanup script to erase their tracks. Key findings: - Initial access began as early as late 2025 via rogue SD-WAN http

    @DFIR_Radar

    26 Jun 2026

    203 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure https://t.co/ny8jMQ6oSi "Mandiant reported that an unknown threat actor exploited Cisco Catalyst SD-WAN vulnerability CVE-2026-20245 (CVSS base score of 7.8) as a zero-day at least two months…"

    @catnap707

    25 Jun 2026

    144 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Urgent: Recent #Cybersecurity flaws impacting data in transit. Apache Log4j TLS bypass (CVE-2026-34478) allows MITM. Cisco SD-WAN zero-day (CVE-2026-20245) grants root, exposing traffic. Patch now! #Vulnerabilities #News

    @YourAnon_irc

    25 Jun 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Mandiant confirmed a threat actor exploited Cisco Catalyst SD-WAN CVE-2026-20245 months before Cisco's June 4 disclosure. The CVSS 7.8 flaw grants root access on SD-WAN controllers. Exploitation started at a service provider in late 2025. Patches available since June 10.

    @XavierRiveraX

    25 Jun 2026

    101 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 A zero-day in Cisco Catalyst SD-WAN (CVE-2026-20245) was exploited in the wild months before it was even disclosed. Mandiant says attackers hit a comms provider, escalating to full root access via a malicious CSV upload. 🔴 Created hidden root account, covered tracks by

    @techepages

    25 Jun 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 💭 Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access Critical CVE / Zero-Day: An unknown threat actor exploited a recently disclosed hig... https://t.co/dySuNCtqbo #CVE #ZeroDay #AI #DataProtection

    @MyDooM15

    25 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Cisco SD-WANのゼロデイ脆弱性CVE-2026-20245は、公式開示の2か月前には悪用され、通信サービス事業者でのrootアクセス取得に使用されていた。Google報告。攻撃の第一波はCVE-2026-20127とCVE-2026-20182を使用し、その後CVE-2

    @__kokumoto

    24 Jun 2026

    841 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  17. New NGINX/QUIC RCE (CVE-2026-42530) and Cisco SD-WAN flaw (CVE-2026-20245) threaten data integrity. Encrypted DNS metadata still exposes privacy. Urgent action needed to secure data in transit. #Cybersecurity #NetworkSecurity #ZeroDay

    @YourAnon_irc

    24 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨June 2026 Recap 🚨New actively exploited vulnerabilities included: 🔹 CVE-2026-0257 (Palo Alto PAN-OS) 🔹 CVE-2026-45247 (Magento RCE) 🔹 CVE-2026-28318 (SolarWinds Serv-U) 🔹 CVE-2026-50751 (Check Point VPN) 🔹 CVE-2026-20245 (Cisco SD-WAN)

    @CoastalCyberSol

    22 Jun 2026

    4 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 CISA has added a new Cisco Catalyst SD-WAN zero-day to its Known Exploited Vulnerabilities catalog. CVE-2026-20245 (CVSS 7.8) — allows arbitrary command execution as root. But here's the dangerous part — attackers are chaining 3 CVEs together: 🔗 CVE-2026-20182 (CVS

    @techepages

    12 Jun 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Top 3 Cybersecurity Threats 🫠CVE-2026-20245 — Cisco Catalyst SD-WAN Manager (Improper Encoding or Escaping of Output; authenticated local attacker can achieve root execution via crafted file). 🫠CVE-2026-7473 — Arista Extensible Operating System (incomplete tunneled-p

    @Dekryptoes

    12 Jun 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog CISA has added these security vulnerabilities to the KEV catalog today. - CVE-2026-20245 (CVSS score: 7.8) - An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager. - CVE-2026-11645

    @techepages

    11 Jun 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Top #CVE to prioritize 👀 - @Android Framework #privesc (CVE-2025-48595) - @SolarWinds Serv-U (CVE-2026-28318) - @Cisco Catalyst SD-WAN Manager (CVE-2026-20245) - @Cisco Unified Communications Manager (CVE-2026-20230) - @Acer Wave 7 routers (CVE-2026-49200/49201) - @UniFi OS

    @stansecure

    10 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  23. ✨ CVE-2026-20245 e CVE-2026-41089: zero-day Cisco SD-WAN e RCE su Netlogon sotto attacco attivo Leggi il blog: https://t.co/ox4yzYugBW https://t.co/eYCip6WhVz

    @nuke86

    10 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Top 3 Cybersecurity Threats 1. CVE-2026-20245 — Cisco Catalyst SD-WAN Manager (improper output encoding; authenticated local attacker can achieve root execution via crafted file). 2. CVE-2026-7473 — Arista Extensible Operating System (incomplete tunneled-packet handling may l

    @Dekryptoes

    10 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. CVE-2026-20245. 0day Intel: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch

    @lyrie_ai

    10 Jun 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  26. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにアリスタネットワークス社EOSのCVE-2026-7473、ChromiumのCVE-2026-11645、Cisco Catalyst SD-WAN ManagerのCVE-2026-20245を追加。対処期限

    @__kokumoto

    9 Jun 2026

    1872 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. 🛡️ We added Arista EOS vulnerability CVE-2026-7473, Google Chromium V8 vulnerability CVE-2026-11645, & Cisco Catalyst vulnerability CVE-2026-20245 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecur

    @CISACyber

    9 Jun 2026

    3950 Impressions

    13 Retweets

    29 Likes

    2 Bookmarks

    1 Reply

    3 Quotes

  28. Cisco ha confermato lo sfruttamento attivo di CVE-2026-20245 nel Catalyst SD-WAN Manager — il settimo zero-day sulla piattaforma dall'inizio del 2026. L'attore UAT-8616, attivo su questi sistemi dal 2023, ha già sfruttato CVE-2026-20127 e CVE-2026-20182 (CVSS 10.0 auth bypass)

    @trinacriatech

    9 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. Cisco has disclosed CVE-2026-20245. The 7th SD-WAN zero-day exploited in 2026. Seven in one year. That is not bad luck. That is a pattern. This one hits Cisco Catalyst SD-WAN Manager and lets an attacker execute commands as root on the management system. Earlier 2026 flaws like

    @ai_dev_official

    9 Jun 2026

    16 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  30. Cisco Catalyst SD-WAN Managerの脆弱性CVE-2026-20245が悪用されています – パッチは提供されていません Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available #HackerNews (Jun 6) https://t.co/JP7oDUQGmj

    @foxbook

    7 Jun 2026

    269 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. New zero-day in Cisco SD-WAN (CVE-2026-20245) actively exploited, no patch available. Palo Alto PAN-OS (CVE-2026-0257) also targeted for auth bypass. Critical risk to data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    7 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. THREAT INTEL: Cisco SD-WAN Manager 0-Day CVE-2026-20245 - actively exploited cmd injection to root, no patch. 9 detections. https://t.co/nGG9EVTbN8 #ThreatIntel #Cisco #0day https://t.co/IqIC9v6F9S

    @threadlinqs

    7 Jun 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🔓 Cisco just disclosed its 7th SD-WAN zero-day of 2026 — CVE-2026-20245, no patch, no workaround. Actively exploited in the wild, pushing malicious configs to enterprise edge devices across all deployment types including FedRAMP.

    @Divinmentis

    6 Jun 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  34. ⚠️ CRITICAL: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available Cisco Catalyst SD-WAN Manager is under active exploitation due to CVE-2026-20245, a high-severity authentication bypass that allows local attackers to execute arbitrary

    @lenngrenm

    6 Jun 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. CVE-2026-20245: Cisco SD-WAN Manager zero-day, actively exploited, no patch yet. Attackers had at least a week before disclosure. If you run Catalyst SD-WAN Manager: restrict management access to trusted IPs only. Treat as compromised until Cisco patches. #CVE #infosec https://t.

    @byte_guard_blog

    6 Jun 2026

    90 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  36. 1/2🚨 Critical Zero-Day Alert: Cisco SD-WAN Manager Under Active Attack (No Patch Yet) 🚨 https://t.co/QN4wt9D6Zc Cisco has just dropped a high-severity security advisory for a new zero-day vulnerability (CVE-2026-20245) affecting the Command-Line Interface (CLI) of Cisco h

    @CyberDhaal

    6 Jun 2026

    113 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  37. Top 5 Trending CVEs: 1 - CVE-2025-48595 2 - CVE-2026-28318 3 - CVE-2026-20245 4 - CVE-2018-17144 5 - CVE-2026-20230 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    6 Jun 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Cisco just disclosed CVE-2026-20245 — the 7th SD-WAN Manager zero-day exploited in the wild in 2026. Authenticated netadmin → root RCE via crafted file upload. If you run Catalyst SD-WAN, patch now. #ZeroDay #InfoSec #Cybersecurity

    @infrasecserv

    6 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Cisco warned that CVE-2026-20245 in Catalyst SD-WAN Manager is under active exploitation. The flaw lets authenticated attackers execute arbitrary commands as root. https://t.co/EH0V2OgvbW #Cisco #CVE #Catalyst #SDWAN #RCE #CybersecurityNews #CyberSecurity #ThreatResQ

    @ThreatResq

    6 Jun 2026

    46 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Urgent Cisco SD WAN Manager zero day vulnerability actively exploited (CVE-2026-20245) https://t.co/7EWvK4ObEQ #patchmanagement

    @eyalestrin

    6 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Cisco SD-WAN got its 7th zero-day IN 2026 — CVE-2026-20245 actively exploited, no patch. Attackers chain auth bypass bugs for root on Catalyst SD-WAN Manager. No workarounds. Audit edge configs. https://t.co/vuWu5xMFOM

    @BunSnack

    6 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/bab2X6wKXX

    @wvipersg

    6 Jun 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/6zvDXHdhUq

    @cloudsecla14661

    6 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/5v8GLFHrYw

    @pigram86

    6 Jun 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/1WJ8LidwSg

    @molari999

    6 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/pL3ByGQxSO

    @TheCyberSecHub

    6 Jun 2026

    437 Impressions

    4 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/jFT59ttegb https://t.co/EOk7YIsWbd

    @evanderburg

    6 Jun 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available https://t.co/kv3xWVsavi https://t.co/Vov1rjCJXQ

    @RigneySec

    6 Jun 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited No Patch Available https://t.co/HtmTHW8GFR

    @TheRabbitPy

    6 Jun 2026

    47 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  50. CVE-2026-20245: Cisco 7th SD-WAN Zero-Day — Unpatched Root Escalation, No Patch Available https://t.co/jwZiMu1UkX

    @seanwalker64354

    6 Jun 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations