Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Summary
Cisco has issued a warning about a critical, unpatched zero-day vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager. This vulnerability allows attackers to escalate privileges to root, and it is already being actively exploited in the wild.
IFF Assessment
FOE
The active exploitation of a high-severity, unpatched zero-day vulnerability represents a significant threat to organizations relying on Cisco SD-WAN Manager.
Severity
7.8
High
Defender Context
Defenders should prioritize patching or implementing mitigating controls for Cisco Catalyst SD-WAN Manager immediately. This zero-day is a prime target for attackers seeking to gain deep control over network infrastructure.