A serious unpatched vulnerability in Cisco's Catalyst SD-WAN Manager is being actively exploited in the wild, with no fix currently available from Cisco. This is the seventh Cisco SD-WAN zero-day exploited so far in 2026.
- What it is: CVE-2026-20245 is a privilege escalation flaw in Cisco Catalyst SD-WAN Manager. Attackers can upload a specially crafted file to gain root-level control of the device. There is currently no patch available.
- Who is affected: Any organisation running Cisco Catalyst SD-WAN Manager. Exploitation requires an authenticated local attacker, which limits the initial attack surface — but anyone already inside your network can use this flaw to gain full control of your SD-WAN infrastructure.
- The risk: A successful exploit gives attackers root access, allowing them to modify network configurations, install backdoors, and intercept or redirect traffic. The threat actor behind recent exploits (UAT-8616) has been observed adding SSH backdoor keys and modifying network configurations after gaining access.
- What to do: Check whether your business uses Cisco Catalyst SD-WAN Manager. Restrict access to the management interface to trusted hosts only. Monitor for unexpected configuration changes, new SSH authorised keys, or unusual admin activity. Apply Cisco's patch as soon as it is released.
We recommend businesses with Cisco SD-WAN contact your IT provider to assess your exposure and confirm appropriate access controls are in place while a patch is pending.
Sources: The Hacker News | SecurityWeek | Help Net Security