LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 9, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20245 to its Known Exploited Vulnerabilities catalog on Jun 9, 2026, with a federal patch deadline of Jun 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute…

This vulnerability affects Cisco Catalyst SD-WAN Manager, the central management component formerly known as SD-WAN vManage. An authenticated local attacker can supply a crafted file that results in arbitrary command execution as root. The issue matters because SD-WAN Manager controls wide-area network policies and device configurations; root-level compromise on this system can affect traffic routing and connected routers across an organization.

How it works

The weakness is categorized as CWE-116, improper encoding or escaping of output. In this class of flaw, user-supplied data is not correctly sanitized before it is processed or written to a location that the system later interprets as commands or configuration. An attacker with local authenticated access supplies a specially formatted file; the software fails to neutralize the content, allowing the operating system to treat portions of the file as executable instructions running with root privileges.

Am I affected? How to find it in your systems

Cisco Catalyst SD-WAN Manager typically runs as a centralized controller, either on-premises or in a cloud-hosted deployment, that manages SD-WAN edge devices. Inventory all instances by reviewing your Cisco SD-WAN deployment documentation, checking installed software packages on management servers, and querying any orchestration or automation tools that track Cisco appliances. Examine the exact software version and configuration settings against the details listed in the vendor advisory, because only certain releases and setups are affected. No public indicators of compromise specific to this vulnerability are documented; monitor authentication logs and file-upload activity on the management host for unusual local file operations performed by administrative accounts.

How to remediate

Apply the vendor update named in the advisory as the primary remediation. After patching, review and restrict local file-handling permissions on the management system to the minimum required accounts, and confirm that administrative interfaces are accessible only from authorized management networks. Revalidate any custom scripts or automation that interact with file uploads or configuration imports.

If you can't patch immediately

Follow the mitigations specified in the vendor instructions. Where the deployment uses cloud services, apply the requirements of CISA BOD 22-01. If mitigations cannot be implemented, discontinue use of the affected product until an update can be applied. In the interim, limit administrative access through network segmentation and monitor privileged sessions on the management host for unexpected command execution.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access and subsequent data exposure. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN Manager
WeaknessCWE-116
Added to CISA KEVJun 9, 2026
Federal patch deadlineJun 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities