What is CVE-2026-20245?
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
Timeline
- 2026-06-04Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-09Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-11First covered in a defend.network daily briefing
- 2026-06-23CISA federal remediation deadline (BOD 22-01)
- 2026-07-21NVD record last updated
CISA Known Exploited Vulnerability
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Affected product
Cisco Catalyst SD-WAN Manager
NVD also lists CPE entries for: Cisco Catalyst Sd-Wan Manager, Cisco Sd-Wan Vsmart Controller
Remediation Steps
- Apply the vendor security update for Cisco Catalyst SD-WAN Manager as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245
- https://nvd.nist.gov/vuln/detail/CVE-2026-20245
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
- Critical Lantronix flaw actively exploited; Cisco SD-WAN zero-day; 27M credentials recovered (2026-06-25)
- Langflow RCE exploited, JDY botnet expands U.S. military targeting, npm security hardened (2026-06-11)
Browse all tracked CVEs in the defend.network CVE database →