Cisco faces an unpatched, actively exploited SD-WAN zero-day (CVE-2026-20245)
Cisco disclosed CVE-2026-20245, a flaw in Catalyst SD-WAN Manager that lets a low-privileged attacker upload a crafted file to run commands as root — its seventh exploited SD-WAN zero-day of 2026. Mandiant reported the bug, no patch exists yet, and Cisco has already observed attackers pushing configuration changes to edge devices. The phrase that should stop you is "seventh of the year": this is a pattern, not an incident.
Why it matters: An SD-WAN controller is one of the highest-value targets in any enterprise network because it's the single pane that manages the edge — root on that box means an attacker can quietly rewrite the configuration of every device it controls, which is exactly what Cisco says is already happening. The absence of a patch turns this from a race-to-remediate into a race-to-detect-and-contain, and most organizations are far better resourced for the former. The seventh-zero-day framing is the part defenders should internalize: a product line getting exploited this repeatedly suggests a systemic weakness in how these controllers are hardened, not a run of bad luck, and it argues for treating the management plane as an assumed-breach zone rather than a trusted one. For anyone running this gear, the immediate move is compensating controls — restricting who can reach the manager, watching for anomalous config pushes — because waiting for a fix isn't a strategy when there isn't one. The broader lesson for the industry is that centralizing network control into a single orchestrator concentrates convenience and catastrophic risk in the same place.