Cisco disclosed active exploitation of CVE-2026-20245, a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager that lets an authenticated attacker with netadmin privileges upload a crafted file and execute arbitrary commands as root. The vulnerability affects all deployment models, including on-premises, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP environments, and Cisco said attackers have already used it in limited incidents to push unauthorized configuration changes to SD-WAN edge devices.
Cisco said the flaw stems from insufficient validation and sanitization of user-supplied input in the CLI processing path, and warned that attackers may obtain the required privileges with valid credentials or by chaining previously disclosed bugs such as CVE-2026-20182 or CVE-2026-20127. No dedicated patch or workaround was available at disclosure, so Cisco urged customers to upgrade to software versions that fix earlier exploited issues, review indicators of compromise such as suspicious entries in /var/log/scripts.log, preserve forensic evidence, collect diagnostics with the command:
request admin-tech
and contact Cisco TAC if compromise is suspected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco published a security advisory for a Cisco Catalyst SD-WAN Manager arbitrary file write vulnerability, identifying a new security issue affecting the product line beyond the previously tracked CVE-2026-20245 disclosure.
CISA updated its Known Exploited Vulnerabilities catalog to include CVE-2026-20245, the actively exploited Cisco Catalyst SD-WAN Manager command injection flaw. The catalog update placed the Cisco issue alongside newly added Chromium and Arista vulnerabilities flagged as exploited in the wild.
Alongside the disclosure, Cisco shared indicators of compromise such as suspicious entries in /var/log/scripts.log and advised customers to preserve forensic evidence, collect admin-tech data, and contact Cisco TAC for compromise assessment. Cisco also recommended upgrading to software versions that already fix the previously exploited CVE-2026-20182 while awaiting a dedicated fix for CVE-2026-20245.
Cisco publicly disclosed CVE-2026-20245, a high-severity command injection and privilege-escalation flaw in Cisco Catalyst SD-WAN Manager that can let an authenticated attacker with netadmin privileges execute commands as root. At disclosure, Cisco said the vulnerability was being actively exploited in the wild, affected all deployment models, and had no dedicated patch or workaround available.
Cisco said it learned in June of active exploitation of CVE-2026-20245 in Catalyst SD-WAN Manager after receiving a report from Mandiant. The observed activity included limited incidents in which attackers pushed unauthorized configuration changes to SD-WAN edge devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
sec.cloudapps.cisco.com
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcecyberscoop.com
Open sourcetheregister.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.