Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026
Cisco informed customers on Thursday about yet another SD-WAN product vulnerability that has been exploited in the wild – the seventh whose exploitation was detected in 2026.
The new vulnerability, which has yet to be patched by Cisco, is tracked as CVE-2026-20245 and it affects the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager.
An authenticated local attacker can exploit it to execute arbitrary commands as root via specially crafted files.
“This vulnerability is due to insufficient validation of user-supplied input,” Cisco explained in its advisory. “An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.”
The networking giant noted that an attacker needs to have ‘netadmin’ privileges on the targeted system to exploit the flaw, which ca be achieved either...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE