VORANT. Threat Intelligence Sign in Get the full feed

Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245)…

critical vulnerability

Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245) being actively exploited in the wild.

The French CERT (CERT-FR) has published an advisory regarding a privilege escalation vulnerability affecting all versions of Cisco Catalyst SD-WAN Manager. The vulnerability is tracked as CVE-2026-20245 and allows an attacker to escalate privileges on affected systems.

Cisco has confirmed that this vulnerability is being actively exploited in the wild, elevating the urgency for organizations running Catalyst SD-WAN Manager to apply patches immediately. The active exploitation status indicates that threat actors have developed working exploits and are targeting vulnerable installations.

Organizations using Cisco Catalyst SD-WAN Manager should consult Cisco's security advisory (cisco-sa-sdwan-privesc-4uxFrdzx) published on June 4, 2026, and apply the available patches as soon as possible. Given the active exploitation and the critical nature of SD-WAN infrastructure in enterprise networks, this vulnerability poses significant risk to affected organizations.

Mentioned in this report

Vulnerabilities CVE-2026-20245KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0699

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free