Cisco reports active exploitation of new vulnerability in Catalyst SD-WAN Manager (heise.de)
0xBASE INTEL BRIEF
- Cisco confirms active exploitation of vulnerability CVE-2026-20245 in Catalyst SD-WAN Manager.
- Attackers need netadmin privileges and can execute commands as root.
- No patch available; mid-May software is recommended.
- Check logs for anomalies in /var/log/scripts.log.
"Cisco warns of a new actively exploited vulnerability (CVE-2026-20245, CVSS 7.8) in Catalyst SD-WAN Manager. Authenticated local attackers with netadmin privileges can execute arbitrary commands as root. No patch is available yet; no temporary mitigations exist. Cisco recommends updating to mid-May software versions and checking logs for signs of compromise."
no comments yet.