All incidents

Cisco Catalyst SD-WAN zero‑day flaw (CVE-2026-20245) exploited months before patch

vulnerabilityclosedJun 5, 2026 — Jun 10, 2026
Cisco Catalyst SD-WAN zero‑day flaw (CVE-2026-20245) exploited months before patch

CISCO disclosed on 4 June 2026 that a zero‑day flaw tracked as CVE‑2026‑20245 in its Catalyst SD‑WAN Manager had been exploited by attackers months before a patch was released.

Evidence points to activity as early as March 2026 according to Google’s threat intelligence team.

The vulnerability, rated CVSS 7.8 HIGH, stems from improper validation in the command‑line interface of the SD‑WAN Controller.

It allows a locally authenticated attacker with netadmin privileges to execute arbitrary commands with root privileges by uploading a specially crafted file or manipulating CLI parameters as detailed by Mandiant.

Mandiant’s investigation showed that the intruders first gained a foothold via SSH using compromised admin credentials, then escalated to root.

After gaining root, they employed anti‑forensic tactics such as deleting temporary files and restoring system configurations to hide their presence as reported by Darkreading.

Although no specific threat actor has been named, the intrusion was linked to a service provider environment observed between late 2025 and March 2026.

This highlights a broader trend where adversaries target network appliances for persistent access before vulnerabilities become public according to Infosecurity Magazine.

Defenders should immediately apply the Cisco security update for CVE‑2026‑20245 and review and restrict privileged accounts on SD‑WAN devices.

They should also enforce multi‑factor authentication for administrative access and monitor SSH and CLI sessions for anomalous commands as advised by SecurityAffairs.

Additional hardening steps include segmenting the management plane, disabling unused CLI features and enabling detailed logging and file integrity checks.

Conducting regular configuration audits can help detect any unauthorized changes early per The Hacker News.

Intelligence briefing updated Jun 25, 2026

CVE-2026-50751 9.3 KEV CVE-2026-11645 8.8 KEV CVE-2026-20245 7.8 KEV CVE-2026-7473 6.9 KEV
Root sourcesec.cloudapps.cisco.com
Timeline Coverage

Swipe to explore timeline