CVE-2026-20245 is a high-severity root privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager and Controller, currently actively exploited.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| catalyst_sd-wan_manager | * | 20.9.9.1 | vulnerable |
| catalyst_sd-wan_manager | 20.10 | 20.12.5.4 | vulnerable |
| catalyst_sd-wan_manager | 20.12.6 | 20.12.6.2 | vulnerable |
| catalyst_sd-wan_manager | 20.13 | 20.15.4.4 | vulnerable |
| catalyst_sd-wan_manager | 20.15.5 | 20.15.5.2 | vulnerable |
| catalyst_sd-wan_manager | 20.16 | 20.18.2.2 | vulnerable |
| catalyst_sd-wan_manager | 26.1 | 26.1.1.1 | vulnerable |
| catalyst_sd-wan_manager | 20.12.7 | 20.12.7 | vulnerable |
| sd-wan_vsmart_controller | * | 20.9.9.1 | vulnerable |
| sd-wan_vsmart_controller | 20.10 | 20.12.5.4 | vulnerable |
| sd-wan_vsmart_controller | 20.12.6 | 20.12.6.2 | vulnerable |
| sd-wan_vsmart_controller | 20.13 | 20.15.4.4 | vulnerable |
| sd-wan_vsmart_controller | 20.15.5 | 20.15.5.2 | vulnerable |
| sd-wan_vsmart_controller | 20.16 | 20.18.2.2 | vulnerable |
| sd-wan_vsmart_controller | 26.1 | 26.1.1.1 | vulnerable |
| sd-wan_vsmart_controller | 20.12.7 | 20.12.7 | vulnerable |
Consult the Cisco Security Advisory published on May 14, 2026, and apply the software updates provided for Catalyst SD-WAN Manager, Controller, and Validator to address the command injection flaw.
Ensure systems are migrated to fixed versions, specifically upgrading from vulnerable versions such as 20.12.7, 20.15.5.2, 20.18.2.2, or 26.1.1.1 to the latest secure releases recommended by Cisco.
Implement the principle of least privilege (PoLP) by auditing and limiting the number of users with netadmin credentials and restricting local CLI access to only essential, trusted administrators.
Regularly verify the integrity of edge device configurations and audit CLI logs for unusual file upload activities, crafted file submissions, or unauthorized root-level command execution.
Organizations should monitor Cisco SD-WAN CLI logs for unusual file upload activity followed by root-level command execution. Specifically, look for netadmin accounts performing actions outside of normal maintenance windows or using the CLI to interact with system-level files. Additionally, use configuration management tools to detect unauthorized changes pushed from the SD-WAN Manager to edge devices. Network signatures should focus on identifying anomalous administrative traffic patterns or unauthorized local access attempts on management interfaces.
Experience superior visibility and a simpler approach to cyber risk management