VORANT. Threat Intelligence Sign in Get the full feed

Cisco SD-WAN privilege escalation actively exploited

critical vulnerability

CVE-2026-20245 in Cisco Catalyst SD-WAN Manager is under active exploitation, allowing authenticated attackers with netadmin privileges to escalate locally; no patch available yet.

On June 4, 2026, Cisco disclosed CVE-2026-20245, a privilege escalation vulnerability in the command-line interface of Cisco Catalyst SD-WAN Manager. The flaw is being actively exploited in the wild and allows an authenticated attacker with netadmin privileges to elevate their access locally. Attackers can obtain the required netadmin privileges through valid credentials or by chaining this vulnerability with CVE-2026-20182 or CVE-2026-20127.

Cisco has not yet released a patch for CVE-2026-20245 and provides no workarounds. The vendor recommends applying security updates from May 14, 2026, which address CVE-2026-20182, and hunting for indicators of compromise that Cisco has published.

Separately, on June 2, 2026, a security researcher disclosed CVE-2026-49975, dubbed "HTTP/2 Bomb," affecting HTTP/2 configurations in multiple widely deployed web servers including F5 nginx (versions prior to 1.29.8), Apache httpd (without mod_http2 v2.0.41), Microsoft IIS (all versions), Envoyproxy envoy (all versions), and Cloudflare Pingora (all versions).

Mentioned in this report

Vulnerabilities CVE-2026-20127KEVCVE-2026-20182KEVCVE-2026-20245KEVCVE-2026-49975

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-025

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free