---
schema: 1
kind: vulnerability
title: >
  CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no
  patch)
headline: >
  CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no
  patch)
summary: >
  Second Cisco Catalyst SD-WAN Manager zero-day under active exploitation (CVE-2026-20245) — a
  post-authentication command-injection that yields root on the appliance; Cisco confirms limited
  in-the-wild use pushing configuration changes to managed edge devices, and there is no patch.
  Reachable to netadmin attackers directly or by chaining the earlier pre-auth bypass
  CVE-2026-20182 (NCSC-CH GovCERT, 2026-06-05).
discovered_at: "2026-06-06T05:00:02Z"
updated_at: "2026-06-27T05:17:48Z"
event_date: 2026-06-05
run_id: 2026-06-06-d01b95fe
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - priv-esc
  - patch-available
  - auth-bypass
regions:
  - global
  - switzerland
sectors:
  - public-sector
  - telco
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-20245
    cvss: n/a
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-20127
    cvss: n/a
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-20182
    cvss: n/a
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx"
    publisher: Cisco PSIRT advisory cisco-sa-sdwan-privesc-4uxFrdzx
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12579"
    publisher: NCSC-CH GovCERT advisory 12579
    role: corroborating
  - url: "https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager"
    publisher: Mandiant/GTIG
    role: primary
closed_sources: []
evidence:
  - quote: "Cisco has confirmed a second actively-exploited zero-day in Catalyst SD-WAN Manager (formerly vManage), tracked as CVE-2026-20245 (Cisco PSIRT; NCSC-CH GovCERT, 2026-06-05)."
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-06-06): When we first noted CVE-2026-20245 it was a fresh Cisco advisory for a command-injection-to-root flaw in Catalyst SD-WAN Manager with confirmed exploitation but little public detail."
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-06-26): Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 (Google Mandiant, 2026-06-24)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Mitigate Cisco Catalyst SD-WAN Manager now — no patch exists** (. Actively exploited to root; ACL the management plane to a dedicated management VLAN, enforce MFA for netadmin, rotate Manager credentials, and confirm the earlier pre-auth bypass CVE-2026-20182 is remediated so the unauth-to-root chain is broken. Hunt the CLI audit log and edge-device config-push events."
updates:
  - at: "2026-06-26T04:54:42Z"
    run_id: 2026-06-26-6bbe4619
    type: update
    summary: >
      Mandiant reconstructs a months-long zero-day compromise of Cisco Catalyst SD-WAN Manager
      (CVE-2026-20245) — updating our 6 June coverage, GTIG details an authenticated request
      tenant-upload CLI command-injection path that planted a troot UID-0 account on the controller,
      reached after a peering-auth-bypass foothold and exploited at a service provider from late 2025
      through March 2026, well before the patch (Mandiant/GTIG, 2026-06-24). Today's deep dive (§5).
      Patch to the fixed trains immediately and audit vManage hosts for OS-level account creation.
    fields:
      - cves
      - evidence
      - sources
      - tags
      - body
    merged_from: 2026-06-26/mandiant-publishes-the-forensic-reconstruction-behind-cisco
  - at: "2026-06-27T05:17:48Z"
    run_id: 2026-06-27-40e791d4
    type: update
    summary: >
      UPDATE (originally covered 2026-06-26): Google Mandiant (GTIG) published (2026-06-24) the first
      complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a
      service-provider victim from late 2025 into 2026 (Google Mandiant, 2026-06-24).
    fields:
      - cves
      - evidence
      - regions
      - tags
      - body
    merged_from: 2026-06-27/mandiant-documents-the-full-cisco-catalyst-sd-wan-exploitati
migrated_from: briefs/2026-06-06.md
---

Cisco has confirmed a second actively-exploited zero-day in Catalyst SD-WAN Manager (formerly vManage), tracked as CVE-2026-20245 ([Cisco PSIRT](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx); [NCSC-CH GovCERT, 2026-06-05](https://security-hub.ncsc.admin.ch/#/posts/12579)). It is a command-injection flaw: an attacker with `netadmin` privileges can inject arbitrary OS commands that execute as **root** on the underlying appliance (`T1059.004` Unix Shell, following `T1078` Valid Accounts). Per Cisco, exploitation requires either valid netadmin credentials or prior exploitation of the pre-auth bypass CVE-2026-20182 (covered in weekly W22) or CVE-2026-20127 — making the realistic path an unauthenticated-to-root chain against an internet-exposed Manager. Cisco states it has "observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices," i.e. the blast radius extends from the management plane to every managed edge router. **No fixed release is available**; Cisco's only guidance is to restrict management-plane access to trusted hosts and verify edge-device configuration. Detection concepts: review the SD-WAN Manager CLI audit log for unexpected command execution and EDR/host telemetry for shells spawned under the management daemon's service account; treat any unplanned config push to edge devices as a hunting trigger. Hardening: ACL the management interface to a dedicated management VLAN, enforce MFA for netadmin, and rotate Manager credentials given confirmed in-the-wild use.

## Update — 2026-06-26T04:54:42Z

When we first noted CVE-2026-20245 it was a fresh Cisco advisory for a command-injection-to-root flaw in Catalyst SD-WAN Manager with confirmed exploitation but little public detail. Mandiant/GTIG has now published the forensic reconstruction, confirming the flaw was used as a **zero-day at a communications service provider from late 2025 through March 2026 — months before the patch** ([Mandiant/GTIG, 2026-06-24](https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager)).

The new substance is the kill chain: a peering-authentication-bypass foothold (CVE-2026-20127 / CVE-2026-20182) into SSH as `vmanage-admin`, then a crafted tenant CSV through the `request tenant-upload` CLI handler injecting commands that planted a backdoor `troot` UID-0 account, with anti-forensic clean-up (admin-password change-then-revert, history/syslog deletion). Mandiant names no threat actor. Full mechanics, ATT&CK mapping and host-level detection are in §5.

## Update — 2026-06-27T05:17:48Z

Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 ([Google Mandiant, 2026-06-24](https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager)). NCSC-CH amended its Security Hub post to add the report on 2026-06-25 ([NCSC-CH Security Hub post 12579](https://security-hub.ncsc.admin.ch/#/posts/12579)).

The chain: authentication bypass via `CVE-2026-20182`/`CVE-2026-20127` (rogue peering connection), then privilege escalation via `CVE-2026-20245` — a malicious `evil_tenant.csv` uploaded through the `request tenant-upload` CLI carries unsanitised shell commands that append a `troot` root user to `/etc/passwd` and `/etc/shadow`, after which the actor reverts configuration changes and deletes the file for anti-forensics. This gives defenders concrete hunts the earlier advisory could not: search SD-WAN Manager instances for unexpected `/etc/passwd` additions, `evil_tenant.csv` artefacts, and `request tenant-upload` execution in CLI logs.
