Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20245

Published 2026-06-04
Updated 2 months ago
Vendor/s
Cisco
Product/s
Catalyst SD-WAN Manager
Version/s
* > 20.9.9.1
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.8
/ 10
High
Severity Details
Base score
7.8 High
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-20245 is a high-severity root privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager and Controller, currently actively exploited.

CPE

Cisco logo
Cisco
Product Version Start Version End (excl.) Status
catalyst_sd-wan_manager * 20.9.9.1 vulnerable
catalyst_sd-wan_manager 20.10 20.12.5.4 vulnerable
catalyst_sd-wan_manager 20.12.6 20.12.6.2 vulnerable
catalyst_sd-wan_manager 20.13 20.15.4.4 vulnerable
catalyst_sd-wan_manager 20.15.5 20.15.5.2 vulnerable
catalyst_sd-wan_manager 20.16 20.18.2.2 vulnerable
catalyst_sd-wan_manager 26.1 26.1.1.1 vulnerable
catalyst_sd-wan_manager 20.12.7 20.12.7 vulnerable
sd-wan_vsmart_controller * 20.9.9.1 vulnerable
sd-wan_vsmart_controller 20.10 20.12.5.4 vulnerable
sd-wan_vsmart_controller 20.12.6 20.12.6.2 vulnerable
sd-wan_vsmart_controller 20.13 20.15.4.4 vulnerable
sd-wan_vsmart_controller 20.15.5 20.15.5.2 vulnerable
sd-wan_vsmart_controller 20.16 20.18.2.2 vulnerable
sd-wan_vsmart_controller 26.1 26.1.1.1 vulnerable
sd-wan_vsmart_controller 20.12.7 20.12.7 vulnerable

Related weakness (CWE)

CWE-116

Remediation plan

1

Apply official patches

Consult the Cisco Security Advisory published on May 14, 2026, and apply the software updates provided for Catalyst SD-WAN Manager, Controller, and Validator to address the command injection flaw.

2

Update affected systems

Ensure systems are migrated to fixed versions, specifically upgrading from vulnerable versions such as 20.12.7, 20.15.5.2, 20.18.2.2, or 26.1.1.1 to the latest secure releases recommended by Cisco.

3

Restrict access

Implement the principle of least privilege (PoLP) by auditing and limiting the number of users with netadmin credentials and restricting local CLI access to only essential, trusted administrators.

4

Monitor for exploitation

Regularly verify the integrity of edge device configurations and audit CLI logs for unusual file upload activities, crafted file submissions, or unauthorized root-level command execution.

Detection Guidance

Organizations should monitor Cisco SD-WAN CLI logs for unusual file upload activity followed by root-level command execution. Specifically, look for netadmin accounts performing actions outside of normal maintenance windows or using the CLI to interact with system-level files. Additionally, use configuration management tools to detect unauthorized changes pushed from the SD-WAN Manager to edge devices. Network signatures should focus on identifying anomalous administrative traffic patterns or unauthorized local access attempts on management interfaces.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management