Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Manager Flaw Exploited Amid Lack of Patch

Cisco SD-WAN Manager Flaw Exploited Amid Lack of Patch

Posted on June 6, 2026 By CWS

Cisco has issued a warning regarding an actively exploited high-severity security flaw in its Catalyst SD-WAN Manager. Known as CVE-2026-20245, this vulnerability has been assigned a CVSS score of 7.8, indicating its potential impact. The flaw affects various deployments, including On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud, and Cisco SD-WAN for Government (FedRAMP).

Vulnerability Details and Impact

The vulnerability stems from inadequate validation of user-supplied input in the CLI of Cisco Catalyst SD-WAN Manager, previously called SD-WAN vManage. This loophole allows a local, authenticated attacker to execute arbitrary commands as the root user by introducing a crafted file to the compromised system. Exploiting this vulnerability requires netadmin privileges, which necessitates either valid credentials or leveraging other vulnerabilities like CVE-2026-20182 or CVE-2026-20127.

CVE-2026-20182, which carries a perfect CVSS score of 10.0, was identified by Rapid7 last month as an authentication bypass vulnerability that could enable remote attackers to gain administrative access without authentication. This vulnerability, along with CVE-2026-20127, has been exploited as zero-days in past incidents linked to a threat group known as UAT-8616.

Cisco’s Advisory and Recommendations

Cisco’s advisory highlights that they have noted a limited number of cases where CVE-2026-20245 exploitation led to configuration changes on edge devices. Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan were credited with identifying and reporting this issue. As of now, no patches or workarounds have been made available for this vulnerability.

Customers using affected systems are urged to upgrade their SD-WAN software to incorporate fixes released for CVE-2026-20182 on May 14, 2026. Cisco also advises that internet-exposed systems are particularly vulnerable and recommends monitoring the “/var/log/scripts.log” file for specific entries that could indicate compromise.

Context and Future Outlook

This recent disclosure of CVE-2026-20245 marks the seventh actively exploited flaw in Cisco SD-WAN products this year, following several other security lapses. Just days prior, Cisco addressed another critical vulnerability in its Unified Communications Manager (CVE-2026-20230), though there is no current evidence of its exploitation.

The continuous identification of such vulnerabilities underlines the importance of maintaining robust security protocols and prompt software updates. As threat actors increasingly exploit these vulnerabilities, organizations must remain vigilant and proactive in safeguarding their network systems.

The Hacker News Tags:Cisco, CVE-2026-20245, Cybersecurity, Exploit, network security, Patch, risk mitigation, SD-WAN, security flaw, Vulnerability

Post navigation

Previous Post: OWASP CVE Lite CLI: Revolutionizing Vulnerability Scanning
Next Post: CISA Alerts to Exploited SolarWinds Serv-U Vulnerability

Related Posts

Google Gemini Vulnerability Exposed by Notifications Google Gemini Vulnerability Exposed by Notifications The Hacker News
Critical n8n Vulnerability Allows System Commands Execution Critical n8n Vulnerability Allows System Commands Execution The Hacker News
Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation The Hacker News
Security Flaw in Claude for Chrome Allows Unauthorized Access Security Flaw in Claude for Chrome Allows Unauthorized Access The Hacker News
Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms The Hacker News
Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zimbra Releases Critical Security Patches for Vulnerabilities
  • AWS Kiro Vulnerability Exposed Code Execution Risk
  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zimbra Releases Critical Security Patches for Vulnerabilities
  • AWS Kiro Vulnerability Exposed Code Execution Risk
  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark