# Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245)…

Published: 2026-06-05 · Severity: critical
Canonical: https://vorant.io/reports/b3fec97e-ed58-4446-bac5-488e1aac7c8a/cisco-catalyst-sd-wan-manager-has-a-privilege-escalation-vulnerability-cve-2026

> Cisco Catalyst SD-WAN Manager has a privilege escalation vulnerability (CVE-2026-20245) being actively exploited in the wild.

The French CERT (CERT-FR) has published an advisory regarding a privilege escalation vulnerability affecting all versions of Cisco Catalyst SD-WAN Manager. The vulnerability is tracked as CVE-2026-20245 and allows an attacker to escalate privileges on affected systems.

Cisco has confirmed that this vulnerability is being actively exploited in the wild, elevating the urgency for organizations running Catalyst SD-WAN Manager to apply patches immediately. The active exploitation status indicates that threat actors have developed working exploits and are targeting vulnerable installations.

Organizations using Cisco Catalyst SD-WAN Manager should consult Cisco's security advisory (cisco-sa-sdwan-privesc-4uxFrdzx) published on June 4, 2026, and apply the available patches as soon as possible. Given the active exploitation and the critical nature of SD-WAN infrastructure in enterprise networks, this vulnerability poses significant risk to affected organizations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20245 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0699

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b3fec97e-ed58-4446-bac5-488e1aac7c8a/cisco-catalyst-sd-wan-manager-has-a-privilege-escalation-vulnerability-cve-2026.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
