CVE-2026-20245: Cisco Catalyst SD-WAN Manager Zero-Day Exploited for Root Escalation — No Patch Available | CyberHawk Threat Intel

Cisco discloses CVE-2026-20245, an unpatched command injection zero-day in Catalyst SD-WAN Manager actively exploited in the wild to gain root. Mandiant reported limited exploitation resulting in edge device config changes.

2026-08-31T22:28:50.720Z
Rudra Verma, Senior Security Architect & Researcher