CVE-2026-20245
CVE-2026-20245: 1 tracked advisory record across Cisco. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityHigh7.8
High [CVE-2026-20127 +2] Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
cisco-sa-sdwan-privesc-4uxFrdzxSource published Source updated
This bulletin covers 3 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful…
- Affected products in this advisory
- Cisco Catalyst SD-WAN Controller
- Cisco Catalyst SD-WAN Manager
- Source-reported affected versions
- Scope: This vulnerability affects Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, and Cisco Catalyst SD-WAN Validator, regardless of device configuration.
- Release 20.9.9.1 and earlier (first fixed: 20.9.9.2)
- Release 20.12.7.1 and earlier (first fixed: 20.12.7.2)
- Release 20.15.4.4 and earlier (first fixed: 20.15.4.5)
3 more entries in the full advisory.
- Source-reported fixed versions
- 20.9.9.2
- 20.12.7.2
- 20.15.4.5
- 20.15.5.3
2 more entries in the full advisory.
- Mitigation guidance
- Cisco recommends that customers upgrade to the fixed software that is documented in the Catalyst SD-WAN Security Advisory that was published on May 14, 2026, and verify the configuration of the edge devices.
- If the logs show indicators of compromise and the system is confirmed to be compromised, applying the software update alone will not resolve the vulnerability.
- The only way to remediate this vulnerability is to upgrade to the first fixed software release, as noted in the Fixed Releases section of this advisory.
- Workarounds
- Live Protect Shield Cisco has released a Live Protect shield for CVE-2026-20245 to provide temporary security coverage to allow time for software upgrade planning, including preserving any information that customers may require for governance or compliance purposes.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.