Cisco Catalyst SD‑WAN Zero‑Day Exploited Before Public Disclosure
Patch Cisco Catalyst SD‑WAN firmware to the latest version that fixes CVE‑2026‑20245.
Patch the Cisco Catalyst SD‑WAN firmware to the latest version that contains the fix for CVE‑2026‑20245.
Summary
An unknown threat actor exploited a recently disclosed high‑severity security flaw in Cisco Catalyst SD‑WAN before it was publicly disclosed, according to new findings from Google‑owned Mandiant.
The vulnerability, identified as CVE‑2026‑20245, carries a CVSS score of 7.8 and allows an authenticated local attacker to execute arbitrary commands with elevated privileges. The flaw was actively exploited at least two months prior to its public disclosure, demonstrating a zero‑day window that could have impacted thousands of SD‑WAN deployments. Mandiant’s investigation traced the exploitation to a sophisticated actor that leveraged the flaw to gain privileged access within the network fabric. Cisco has released a patch that mitigates the issue by tightening privilege checks on command execution. Network administrators should verify that their SD‑WAN firmware is updated to the latest version and monitor logs for anomalous command activity. Failure to patch could leave the network vulnerable to remote code execution and potential lateral movement by attackers.
Key changes
- CVE‑2026‑20245 identified
- CVSS score 7.8
- Authenticated local attacker can execute arbitrary commands with elevated privileges
- Exploited at least two months before public disclosure
- Mandiant investigation revealed sophisticated actor
- Cisco released patch tightening privilege checks
- Firmware update required
- Zero‑day exploitation window demonstrated