Attackers have actively exploited multiple vulnerabilities in Cisco Catalyst SD-WAN Manager (vManage) to bypass authentication, escalate privileges to root, and alter downstream network infrastructure. Reporting on the campaign says the intrusion chain used critical auth-bypass flaws CVE-2026-20127 and CVE-2026-20182 for initial access, then leveraged CVE-2026-20245 to execute commands as root through crafted file upload and command injection in the CLI. Cisco confirmed limited incidents in which exploitation led to configuration changes being pushed to edge devices, raising the risk that compromise of a single controller could affect broad SD-WAN environments.
Cisco also disclosed active exploitation of CVE-2026-20262, a separate zero-day in Cisco Catalyst SD-WAN Manager that lets an authenticated low-privilege attacker abuse file-upload handling to create or overwrite files on the underlying operating system and gain root privileges. The flaw affects on-premises, Cloud, Cloud-Pro, and FedRAMP deployments, and Cisco released fixes in versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. U.S. authorities added exploited Cisco SD-WAN flaws to the Known Exploited Vulnerabilities catalog, and CISA issued Emergency Directive 26-03 directing federal agencies to hunt for compromise and rapidly harden affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
CISA issued Emergency Directive 26-03 requiring federal agencies to hunt for compromise and harden affected Cisco SD-WAN systems within two days. The directive followed active exploitation of multiple Cisco Catalyst SD-WAN Manager vulnerabilities.
Reporting described a 2026 intrusion chain targeting Cisco Catalyst SD-WAN Manager in which attackers used authentication bypass flaws CVE-2026-20127 and CVE-2026-20182 with CVE-2026-20245 to gain root access. The activity was attributed to the UAT-8616 threat cluster and included unauthorized peering, SSH access as vmanage-admin, privilege escalation, creation of a hidden UID 0 account, and anti-forensic cleanup.
Cisco released security updates for CVE-2026-20262 after confirming active exploitation in the wild against Cisco Catalyst SD-WAN Manager. The vulnerability lets an authenticated low-privilege attacker abuse file uploads to create or overwrite files and escalate privileges to root.
CISA added CVE-2026-20245 to its Known Exploited Vulnerabilities catalog on June 9, 2026. The listing reflected active exploitation of the Cisco Catalyst SD-WAN privilege-escalation flaw.
Cisco said it was aware of exploitation of CVE-2026-20245 in June 2026. The company also observed limited cases where exploitation led to configuration changes being pushed to edge devices.
Cisco documented fixed software for CVE-2026-20245 in a security advisory dated May 14, 2026. The flaw allows an authenticated local attacker with netadmin privileges to upload a crafted file and execute commands as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcethreataft.com
Open sourcevulnerability.circl.lu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.