CISA KEV · Known exploitedHigh

CVE-2026-20245

Cisco Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, catalyst sd-wan manager

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks o...

CVSS
7.8
EPSS
25.3%
97.7% percentile
CISA KEV
Listed
Published
2026.06.05
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability25.3%
Technical severityCVSS 7.8

Vulnerability overview

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks o...

Affected product and versions

Product
Cisco Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, catalyst sd-wan manager
Affected versions
>= 20.6.4, >= 20.9.2, >= 20.3.6, >= 20.7.2, >= 20.7.1, >= 20.5.1, >= 20.6.2, >= 19.3.0, >= 20.6.1, >= 17.2.4, >= 18.2.0, >= 18.4.6, >= 19.1.0, >= 19.2.4, >= 19.2.929, >= 18.3.8, >= 18.4.303, >= 18.3.7, >= 18.4.1, >= 19.2.097
Fixed versions
20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, 26.1.1.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due date: 2026.06.23
  1. 1
    Identify

    Confirm that Cisco Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, catalyst sd-wan manager and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-116
KEV added
2026.06.09
Ransomware use
미확인
CVE-2026-20245 — Cisco Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, catalyst sd-wan manager | SECUFOCUS NOW