Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Manager Flaw Exploited Amid Lack of Patch

Cisco SD-WAN Manager Flaw Exploited Amid Lack of Patch

Posted on June 6, 2026 By CWS

Cisco has issued a warning regarding an actively exploited high-severity security flaw in its Catalyst SD-WAN Manager. Known as CVE-2026-20245, this vulnerability has been assigned a CVSS score of 7.8, indicating its potential impact. The flaw affects various deployments, including On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud, and Cisco SD-WAN for Government (FedRAMP).

Vulnerability Details and Impact

The vulnerability stems from inadequate validation of user-supplied input in the CLI of Cisco Catalyst SD-WAN Manager, previously called SD-WAN vManage. This loophole allows a local, authenticated attacker to execute arbitrary commands as the root user by introducing a crafted file to the compromised system. Exploiting this vulnerability requires netadmin privileges, which necessitates either valid credentials or leveraging other vulnerabilities like CVE-2026-20182 or CVE-2026-20127.

CVE-2026-20182, which carries a perfect CVSS score of 10.0, was identified by Rapid7 last month as an authentication bypass vulnerability that could enable remote attackers to gain administrative access without authentication. This vulnerability, along with CVE-2026-20127, has been exploited as zero-days in past incidents linked to a threat group known as UAT-8616.

Cisco’s Advisory and Recommendations

Cisco’s advisory highlights that they have noted a limited number of cases where CVE-2026-20245 exploitation led to configuration changes on edge devices. Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan were credited with identifying and reporting this issue. As of now, no patches or workarounds have been made available for this vulnerability.

Customers using affected systems are urged to upgrade their SD-WAN software to incorporate fixes released for CVE-2026-20182 on May 14, 2026. Cisco also advises that internet-exposed systems are particularly vulnerable and recommends monitoring the “/var/log/scripts.log” file for specific entries that could indicate compromise.

Context and Future Outlook

This recent disclosure of CVE-2026-20245 marks the seventh actively exploited flaw in Cisco SD-WAN products this year, following several other security lapses. Just days prior, Cisco addressed another critical vulnerability in its Unified Communications Manager (CVE-2026-20230), though there is no current evidence of its exploitation.

The continuous identification of such vulnerabilities underlines the importance of maintaining robust security protocols and prompt software updates. As threat actors increasingly exploit these vulnerabilities, organizations must remain vigilant and proactive in safeguarding their network systems.

The Hacker News Tags:Cisco, CVE-2026-20245, Cybersecurity, Exploit, network security, Patch, risk mitigation, SD-WAN, security flaw, Vulnerability

Post navigation

Previous Post: OWASP CVE Lite CLI: Revolutionizing Vulnerability Scanning
Next Post: CISA Alerts to Exploited SolarWinds Serv-U Vulnerability

Related Posts

Safeguarding AI Agents Through Effective Delegation Safeguarding AI Agents Through Effective Delegation The Hacker News
Webworm Uses Discord and MS Graph for New Backdoors Webworm Uses Discord and MS Graph for New Backdoors The Hacker News
BAS Is the Power Behind Real Defense BAS Is the Power Behind Real Defense The Hacker News
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems The Hacker News
Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency The Hacker News
SloppyLemming Uses New Malware Chains on South Asian Governments SloppyLemming Uses New Malware Chains on South Asian Governments The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark