CVE-2026-20245: Cisco Catalyst SD-WAN Manager Zero-Day Exploited for Root Escalation — No Patch Available | CyberHawk Threat Intel
Cisco discloses CVE-2026-20245, an unpatched command injection zero-day in Catalyst SD-WAN Manager actively exploited in the wild to gain root. Mandiant reported limited exploitation resulting in edge device config changes.
Rudra Verma, Senior Security Architect & Researcher