Cisco has disclosed a high-severity zero-day vulnerability in its Catalyst SD-WAN Manager that attackers are actively exploiting to gain root-level access. The flaw remains unpatched.
Cisco disclosed CVE-2026-20245, a critical vulnerability affecting Cisco Catalyst SD-WAN Manager, on Thursday. The zero-day enables attackers to escalate privileges to root level on affected systems.
The vulnerability is being actively exploited in the wild, according to Cisco's advisory. The company provided no immediate timeline for a security patch, though it confirmed the issue requires urgent remediation.
SD-WAN (Software-Defined Wide Area Network) technology is widely deployed across enterprise networks to optimize traffic routing and reduce costs. Cisco's Catalyst SD-WAN Manager serves as a centralized control point for managing SD-WAN infrastructure, making it a critical asset for organizations relying on this architecture.
Root privilege escalation represents a severe threat, granting attackers complete control over affected systems. From this position, adversaries can install persistent backdoors, exfiltrate sensitive data, or move laterally within networks to compromise additional infrastructure.
Cisco has not disclosed the attack vector or technical details of the vulnerability pending patch availability. The company recommends organizations immediately review their SD-WAN deployments and implement network segmentation to limit access to the Catalyst SD-WAN Manager.
Until a patch is released, Cisco suggests applying additional access controls, monitoring for suspicious activity, and isolating affected systems where possible. The company typically provides security updates through its standard advisory channels.
This disclosure adds to mounting pressure on enterprise security teams managing Cisco infrastructure, following several high-impact vulnerabilities in Cisco products over the past year. Organizations should prioritize testing and deploying the security update immediately upon release.
AegisAI, a security startup founded by former Google executives, secured $36 million in funding to deploy AI agents that detect sophisticated spear phishing attacks.
The US government issued an updated advisory warning that Iranian hackers are actively disrupting critical infrastructure systems used by American water and energy providers.
Apple has published SOC 3 audit reports for its Private Cloud Compute infrastructure, providing third-party verification of security controls for on-device AI processing that routes some tasks to Apple servers.
A developer discovered their coding interview assignment included hidden malware designed to execute via Git hooks. The sophisticated setup raised questions about interview practices and candidate vetting.