CISCO Security Advisory

Published Date: June 5, 2026

CVE: CVE-2026-20245

Advisory Summary

⬢ Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability – Critical Alert ⬢

A high-severity vulnerability (CVE-2026-20245) has been identified in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as root by uploading a crafted file to the system. The root cause is insufficient validation of user-supplied input, enabling command injection and privilege escalation.

🛡️ Recommended Actions:

This advisory underscores the importance of timely patch management and monitoring of privileged accounts within SD-WAN environments. Organizations using Cisco Catalyst SD-WAN Manager should prioritize this update to mitigate risks of severe unauthorized control of their networks.

🔗

-WAN -2026-20245

Reference: Vendor Advisory