CVE-2026-20245
Confirmed PUBLISHEDCisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
4 days faster than CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
- CVE Published
- Jun 04, 2026
- Exploitation Reported
- Jun 05, 2026
- CVSS
- 7.8 High
- EPSS
- 25.3%
Affected Versions
518 version rows · page 1 of 21
| Vendor | Product | Version | Status |
|---|---|---|---|
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.6.4 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.9.2 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.3.6 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.7.2 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.7.1 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.5.1 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.6.2 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.3.0 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.6.1 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
17.2.4 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.2.0 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.4.6 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.1.0 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.2.4 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.2.929 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.3.8 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.4.303 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.3.7 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.4.1 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.2.097 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.2.0 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.2.099 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
18.3.6 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
20.4.2 |
Affected |
| Cisco |
Cisco Catalyst SD-WAN Controller
|
19.0.0 |
Affected |
CVE References
- cisco-sa-sdwan-privesc-4uxFrdzx sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...
- CVE-2026-20182</a> or <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" target="_blank" rel="noopener">CVE-2026-20127 sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| BleepingComputer First | 2026-06-05 06:24 UTC |
| TheHackerNews | 2026-06-06 06:20 UTC |
| CISA | 2026-06-09 19:00 UTC |
| CVE | 2026-06-09 19:31 UTC |
| All CISA Advisories | 2026-06-09 20:20 UTC |
| Google Threat Intelligence | 2026-06-24 14:20 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2026-06-05 06:24:20 UTC · BleepingComputer
Proof of concept available
Recorded 2026-06-10 15:42:52 UTC · GitHub
Weaknesses (CWE)
-
Improper Encoding or Escaping of Output
Recent Mentions
TheHackerNews · Jun 25, 2026
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges
BleepingComputer · Jun 24, 2026
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
Google Threat Intelligence · Jun 24, 2026
Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities. Key Observations Rogue Peering and Credential Manipulation: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection. Exploitation of CVE-2026-20245: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload. Extensive Anti-Forensic Cleanup: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged. What is SD-WAN? Traditional Wide Area Networks (WANs) rely heavily on physical, proprietary hardware routers to direct traffic. This model is often rigid, complex to scale, and struggles to handle the demands of modern cloud computing. Software-Defined Wide Area Network (SD-WAN) solves this by decoupling the network’s management and control logic from the underlying physical hardware. Instead of configuring individual routers one by one, a centralized software controller is used to orchestrate the entire...
Google Threat Intelligence · Jun 24, 2026
Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities. Key Observations Rogue Peering and Credential Manipulation: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection. Exploitation of CVE-2026-20245: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload. Extensive Anti-Forensic Cleanup: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged. What is SD-WAN? Traditional Wide Area Networks (WANs) rely heavily on physical, proprietary hardware routers to direct traffic. This model is often rigid, complex to scale, and struggles to handle the demands of modern cloud computing. Software-Defined Wide Area Network (SD-WAN) solves this by decoupling the network’s management and control logic from the underlying physical hardware. Instead of configuring individual routers one by one, a centralized software controller is used to orchestrate the entire network from a single...
TheHackerNews · Jun 10, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The list of vulnerabilities is as follows - CVE-2026-20245 (CVSS score: 7.8) - An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager that could allow an
Cisco Security Advisory · Jun 09, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the Catalyst SD-WAN Security Advisory that was published on May 14, 2026, and verify the configuration of the edge devices. Cisco has released software updates that address this vulnerability. This advisory will be updated as more information becomes available. There are no workarounds that address this vulnerability. Important: To preserve possible indicators of compromise, customers should issue the request admin-tech command from each of the control components in the SD-WAN deployment before upgrading. After the admin-tech file has been collected, software should be upgraded at the earliest opportunity. Before upgrading an SD-WAN deployment to a fixed release, retain relevant logs. After upgrading, verify that the system has not been compromised by checking the logs for the indicators of compromise as documented in this advisory. If the logs show...
All CISA Advisories · Jun 09, 2026
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
TheHackerNews · Jun 06, 2026
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types - On-Prem Deployment Cisco SD-WAN Cloud-Pro Cisco SD-WAN Cloud (Cisco Managed) Cisco SD-WAN for Government (FedRAMP) "A
BleepingComputer · Jun 05, 2026
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. [...]
Cisco Security Advisory · Jun 04, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the Catalyst SD-WAN Security Advisory that was published on May 14, 2026, and verify the configuration of the edge devices. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Important: To preserve possible indicators of compromise, customers should issue the request admin-tech command from each of the control components in the SD-WAN deployment before upgrading. After the admin-tech file has been collected, software should be upgraded at the earliest opportunity. Before upgrading an SD-WAN deployment to a fixed release, retain relevant logs. After upgrading, verify that the system has not been compromised by checking the logs for the indicators of compromise as documented in this advisory. If the logs show indicators of compromise and the system is confirmed to be compromised, applying the software update alone will not resolve the vulnerability. In such cases, follow the specific...
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-06-10 15:42:52 UTC · 0 stars
**Este código es SOLO para fines educativos y pruebas de seguridad autorizadas.**
github · Created 2026-06-06 04:26:16 UTC · 0 stars
CVE-2026-20245 - Cisco SD-WAN - Draft
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
14:20 UTC 26 days ago14:20 UTC · 26 days ago
KEV confirmed by Google Threat Intelligence
Exploitation attested by an external source
-
20:20 UTC about 1 month ago20:20 UTC · about 1 month ago
KEV confirmed by All CISA Advisories
Exploitation attested by an external source
-
19:31 UTC about 1 month ago19:31 UTC · about 1 month ago
KEV confirmed by CVE
Exploitation attested by an external source
-
19:00 UTC about 1 month ago19:00 UTC · about 1 month ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
06:20 UTC about 1 month ago06:20 UTC · about 1 month ago
KEV confirmed by TheHackerNews
Exploitation attested by an external source
-
04:26 UTC about 1 month ago04:26 UTC · about 1 month ago
Public PoC available
Public proof-of-concept code published
-
06:24 UTC about 2 months ago06:24 UTC · about 2 months ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
22:33 UTC about 2 months ago22:33 UTC · about 2 months ago
CVE published
Vulnerability disclosed publicly
-
11:59 UTC 10 months ago11:59 UTC · 10 months ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-20245
{
"cve_id": "CVE-2026-20245",
"title": "Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerabi...",
"affected_vendor": "Cisco",
"affected_product": "Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": 0.25323,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}