A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform’s file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack.
First seen on thecyberexpress.com
Jump to article: thecyberexpress.com/cve-2026-20245-cisco-catalyst/
![]()

