Last Updated: 2026-06-25T15:47:43Z
What’s Happening
As of Friday, June 12th 2026, Cisco updated their initial advisory. It now has a patch available.
Cisco has released an advisory for a High Severity, Privilege Escalation in Cisco Catalyst SD-WAN, CVE-2026-20245. The vulnerability currently has no patch available. It has no workarounds. It has been reported by Cisco as EITW. It does however require netadmin credentials (or the exploitation of vulnerabilities from previous advisories CVE-2026-20182, CVE-2026-20127).
Cisco’s Advisory for the Privilege Escalation Vuln:
Cisco’s Advisories for the Authentication Bypass Vulns from May/February:
CVE-2026-20182 - This vuln has a POC and available metasploit module from Rapid7.
CVE-2026-20127 - This vuln has a POC available from ZeroZenX labs.
IOCs Provided by Cisco
Monitor /var/log/scripts.log for similar log entries. The logs will not determine if an entry is malicious and each entry will need to be reviewed for false positives.
Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0
Mandiant has produced a report on exploitation of this vulnerability.
Actions
Update Cisco SD-WAN to the latest version.
Monitor /var/log/scripts.log for the IOC’s provided by Cisco.
Do not expose Cisco SD-WAN to the public internet. If your instance of Cisco SD-WAN was exposed, we suggest rotating credentials (since netadmin credentials are required if the system is up to date).
Monitor for suspicious password change events in Cisco logs.
Notes
Previous reporting on the Cisco Catalyst SD-WAN vulnerabilities:
https://discourse.ifin.network/t/cve-2026-20182-cisco-catalyst-sd-wan-eitw/457
https://discourse.ifin.network/t/cisco-sd-wan/139
https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
The POCs for the patched Authentication Bypass Vulnerabilities:
https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE
NIST CVE Entry: