Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245)…
Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245) being actively exploited in the wild.
The French CERT (CERT-FR) has published an advisory regarding a privilege escalation vulnerability affecting all versions of Cisco Catalyst SD-WAN Manager. The vulnerability is tracked as CVE-2026-20245 and allows an attacker to escalate privileges on affected systems.
Cisco has confirmed that this vulnerability is being actively exploited in the wild, elevating the urgency for organizations running Catalyst SD-WAN Manager to apply patches immediately. The active exploitation status indicates that threat actors have developed working exploits and are targeting vulnerable installations.
Organizations using Cisco Catalyst SD-WAN Manager should consult Cisco's security advisory (cisco-sa-sdwan-privesc-4uxFrdzx) published on June 4, 2026, and apply the available patches as soon as possible. Given the active exploitation and the critical nature of SD-WAN infrastructure in enterprise networks, this vulnerability poses significant risk to affected organizations.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0699
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free