Cisco Discloses Another Exploited SD-WAN Manager Zero-Day, CVE-2026-20245, With No Patch Yet and a Crafted File Path to Root
Cisco says CVE-2026-20245, a 7.8-rated command-injection flaw in Catalyst SD-WAN Manager, is being exploited to gain root. No patch or workaround is available; Mandiant reported it.