CVE-2026-20245
Description
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzxnvdVendor Advisory
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SWnvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
31- 29th June – Threat Intelligence ReportCheck Point Research · Jun 29, 2026
- Breach Roundup: How Hackers Exploited a Cisco SD-WAN FlawGovInfoSecurity · Jun 26, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 26SentinelOne Labs · Jun 26, 2026
- Cisco Vulnerability Exploited Months Before Disclosure, Google WarnsInfosecurity Magazine · Jun 25, 2026
- Cisco SD-WAN Zero-Day Exploited Months Before PatchingSecurityWeek · Jun 25, 2026
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessThe Hacker News · Jun 25, 2026
- The hits keep on coming for Cisco vulnerabilitiesThe Register Security · Jun 24, 2026
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root accessBleepingComputer · Jun 24, 2026
- Attackers Hit Cisco SD-WAN Flaw 2 Months Before DisclosureDark Reading · Jun 24, 2026
- Malicious hackers exploit Cisco zero-day for highest access level at communications service providerCyberScoop · Jun 24, 2026
- Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level AccessCyber Security News · Jun 24, 2026
- Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN ManagerMandiant Threat Intelligence · Jun 24, 2026
- Cisco adds another SD-WAN box to max-severity bug advisoryThe Register Security · Jun 17, 2026
- Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)Help Net Security · Jun 16, 2026
- Cisco Patches Another SD-WAN Zero-Day Exploited in AttacksSecurityWeek · Jun 16, 2026
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawThe Hacker News · Jun 16, 2026
- Cisco SD-WAN make-me-root bug under attackThe Register Security · Jun 15, 2026
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacksBleepingComputer · Jun 15, 2026
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active ExploitationThe Hacker News · Jun 10, 2026
- No Patch Planned for Exploited Arista EOS VulnerabilitySecurityWeek · Jun 10, 2026
- Cisco customers encounter another SD-WAN zero-day under attackCyberScoop · Jun 9, 2026
- Cisco: CVE-2026-20245 Added to CISA KEV Under Active ExploitationVypr Intelligence · Jun 9, 2026
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and MoreThe Hacker News · Jun 8, 2026
- Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security · Jun 7, 2026
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · Jun 6, 2026
- Yet another Cisco SD-WAN 0-day under attack, and no patch in sightThe Register Security · Jun 5, 2026
- Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)Help Net Security · Jun 5, 2026
- Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root UserCyber Security News · Jun 5, 2026
- Cisco warns of unpatched SD-WAN zero-day exploited in attacksBleepingComputer · Jun 5, 2026
- Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026SecurityWeek · Jun 5, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts