🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Cisco Catalyst SD-WAN Manager Privilege Escalation RCE (CVE-2026-20245) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 5, 2026
CVECVE-2026-20245
CVSS Score7.8
Affectedcatalyst_sd-wan_manager, sd-wan_vsmart_controller
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:High
📋Executive Summary
Cisco disclosed an unpatched zero-day in Catalyst SD-WAN Manager tracked as CVE-2026-20245 that allows local attackers with netadmin privileges to escalate to root by uploading a crafted file and injecting commands. Active exploitation has been confirmed by Mandiant, with observed cases where successful exploitation resulted in configuration changes being pushed to edge devices. No patch exists yet, and the vulnerability affects every deployment model including on-prem, cloud-managed, and FedRAMP environments.
⚠️Why It Matters for MSSPs
If you manage client network infrastructure that includes Cisco Catalyst SD-WAN, a compromised SD-WAN Manager means an attacker with root on that system can push configuration changes to every edge device that manager controls, which is a single point of failure for your entire client WAN topology. On your own stack, if you use SD-WAN Manager to monitor multi-site clients from one dashboard, that dashboard is now an attacker-controlled pivot point into every client site it touches. Saying nothing to clients running this today is a contract liability, not just a retention risk.
✅Recommended Action
Audit every client environment and your own stack for Cisco Catalyst SD-WAN Manager deployments in the next 24 hours, check the /var/log/scripts.log file for the IOC pattern Cisco published, open a Cisco TAC case immediately for any system you cannot verify as clean, and push a direct client advisory tonight naming the CVE and the configuration-change risk.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.