Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation

A command-injection bug in Catalyst SD-WAN Manager is already being used in the wild. No patch exists yet — and a known espionage group may be involved.

ThreatVectr Newsdesk· 2 min read
Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation
Share

Cisco is warning that attackers are actively exploiting a high-severity privilege-escalation flaw in Catalyst SD-WAN Manager before the company has shipped a fix.

The vulnerability, CVE-2026-20245, lives in the command-line interface. An authenticated attacker who reaches it can inject commands and escalate to root — full system takeover. CVSS scores it 7.8, not critical, because exploitation requires local access and netadmin credentials. That caveat matters less than it sounds. Netadmin credentials are exactly the kind of thing stolen credential markets and earlier auth-bypass flaws hand an attacker on a plate.

Those earlier bypasses are directly relevant. CVE-2026-20127 — patched in February — and a second auth-bypass fixed in May were both exploited by a cyberespionage cluster Cisco Talos tracks as UAT-8616, a group that has made SD-WAN infrastructure something of a specialty. Whether UAT-8616 is also behind the current exploitation is not confirmed. Mandiant — Google's incident-response division — reported this new bug to Cisco, which hints at active intrusions rather than a researcher fuzzing a lab box.

Cisco's advisory describes the root cause plainly: insufficient validation of user-supplied input. The attacker uploads a crafted file; the system executes attacker-controlled commands. Classic command injection — no novel AI primitives required.

With no patch available, Cisco's guidance is partial. Upgrade to the latest release to eliminate the older auth-bypass paths, reducing the population of attackers who can reach the new flaw. Check edge-device configurations because Cisco has already observed exploitation producing unauthorized configuration changes. Before upgrading, save log files and run request admin-tech on each control component to collect forensic material.

The indicators of compromise live in scripts.log under /var/log/. There is a catch: legitimate and malicious command calls look similar in that log. If you see the IoCs, Cisco says call the Technical Assistance Center rather than assume a software update will clean the environment. The company is explicit that patching a confirmed compromise is not sufficient — TAC will provide specific remediation steps.

SD-WAN management planes are high-value targets precisely because they sit above the data plane. Compromise one controller and configuration changes ripple across an entire enterprise WAN. UAT-8616's repeated interest in this product family is not accidental.

© 2026 Threat Vectr