SYS::ONLINE
Wasteland.
Briefs1223
Issues19
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-20245 2026-06-09

Cisco Catalyst SD-WAN Manager Root Command Injection (CVE-2026-20245)

"CISA has added CVE-2026-20245, a high-severity flaw in Cisco's Catalyst SD-WAN product family that lets an authenticated local attacker execute commands as root, to its Known Exploited Vulnerabilities catalog."

CISA has added CVE-2026-20245, a high-severity flaw in Cisco's Catalyst SD-WAN product family that lets an authenticated local attacker execute commands as root, to its Known Exploited Vulnerabilities catalog.

What Is It

CVE-2026-20245 is an improper encoding or escaping of output vulnerability (CWE-116) in the CLI of Cisco Catalyst SD-WAN products. It stems from insufficient validation of user-supplied input. An authenticated, local attacker can upload a crafted file to the affected system to perform command injection and execute arbitrary commands as the root user. To exploit it, the attacker must hold netadmin privileges, which requires valid credentials. The flaw carries a CVSS 3.1 base score of 7.8 (HIGH), with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

Successful exploitation grants root-level privilege escalation on core SD-WAN management infrastructure. Cisco has observed limited cases where exploitation resulted in a configuration change being pushed to edge devices; meaning a single compromised controller can propagate unauthorized changes downstream across a network fabric. CISA added the CVE to its KEV catalog on June 9, 2026, signaling it warrants priority attention. Known ransomware campaign use is listed as Unknown.

What's Vulnerable

The vulnerability affects the CLI of: - Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) - Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) - Cisco Catalyst SD-WAN Validator (formerly SD-WAN vBond)

Patch Status

Cisco recommends upgrading to the fixed software documented in its advisory published on May 14, 2026, and verifying the configuration of edge devices afterward. Per CISA's required action, organizations must apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The KEV remediation due date is June 23, 2026.

Sources