Cisco has disclosed a critical privilege escalation vulnerability, CVE-2026-20245, affecting Catalyst SD-WAN Manager for which no patch is currently available. Attackers are actively leveraging this zero-day flaw, and Cisco has observed limited instances where exploitation resulted in unauthorized configuration changes being pushed to edge devices. This activity follows previous campaigns by threat actor UAT-8616, who utilized similar authentication bypass vulnerabilities to compromise SD-WAN systems earlier this year.
Source