Cisco has issued an advisory warning about a high-severity, unpatched zero-day vulnerability in its Catalyst SD-WAN Manager that is actively exploited in attacks. The flaw is tracked as CVE-2026-20245 and is associated with root-level privilege escalation, with reporting also describing the potential for arbitrary command execution as root. The affected components include multiple Catalyst SD-WAN Manager deployment types, covering on-premises and cloud offerings, including Cisco SD-WAN Cloud, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), as well as Cisco SD-WAN Cloud-Pro.

Cisco characterizes exploitation as requiring netadmin privileges on an affected system, which would typically involve valid credentials or the use of other vulnerabilities to gain the necessary access. Cisco states it has not seen evidence of other exploitation methods beyond the prerequisite access conditions, and some coverage notes that observed exploitation appears limited. As of the warnings, Cisco has not released a patch for CVE-2026-20245, and the advisory focuses on the presence of active exploitation and the urgency of mitigation planning.