Cisco disclosed a critical command injection flaw in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) that is being actively exploited in the wild, allowing an authenticated local attacker with netadmin privileges to execute arbitrary commands as root. The vulnerability is caused by insufficient validation of file-transfer payloads in the CLI, and Cisco said observed exploitation has already resulted in unauthorized configuration changes being pushed from the manager to edge devices, raising the risk of broader network compromise in affected SD-WAN environments.
Cisco also warned the issue could be chained with the previously disclosed authenticated privilege-escalation bug CVE-2026-20182 to obtain the required access level before triggering command execution. At the time of disclosure, no standard software fix was available; administrators were advised to review logs, inspect scripts.log for suspicious activity, and work with Cisco Technical Assistance Center for mitigations and workarounds while assessing whether managed edge infrastructure had been altered.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco disclosed that CVE-2026-20245, a critical command injection flaw in Cisco Catalyst SD-WAN Manager, was being actively exploited in the wild as of June 2026. Observed exploitation led to configuration changes being pushed to edge devices, and Cisco said no standard patch was yet available while mitigations were provided through TAC.
Acer released firmware version W6x_GBL_2.00.000008 or later for affected Connect W6x consumer wireless devices. The update fixes critical flaws including CVE-2026-49197 and CVE-2026-49199, along with three additional high-severity vulnerabilities.
On June 4, 2026, CVE records were published for several Acer issues, including CVE-2026-49190, CVE-2026-49193, CVE-2026-50206, CVE-2026-50207, and CVE-2026-50209. The entries describe impacts ranging from command injection and unauthorized command execution to public telemetry exposure and MDM endpoint takeover.
An Acer community security advisory about an upcoming firmware update for the Acer Connect M6E 5G Portable WiFi Router was published. This advisory is cited by later CVE records tied to multiple Acer vulnerabilities.
Cisco published a security advisory for an authenticated privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager. The advisory corresponds to CVE-2026-20182, which was later noted as chainable with CVE-2026-20245.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecommunity.acer.com
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.