CVE-2026-20245: Cisco Discloses 7th SD-WAN Zero-Day of 2026 — Unpatched Root Escalation, No Patch Available, Chains After CVSS 10.0 Auth Bypass
Cisco disclosed CVE-2026-20245 on June 5 — the 7th Cisco SD-WAN vulnerability confirmed exploited in 2026. A high-severity command injection in Cisco Catalyst SD-WAN Manager allows root privilege escalation via a crafted file upload. No patch exists. No timeline provided. Discovered by Mandiant during active exploitation investigation. The vulnerability chains directly after CVE-2026-20182 and CVE-2026-20127, both CVSS 10.0. Configuration changes were pushed to edge devices in confirmed exploitation cases. UAT-8616 confirmed involved.
