Affected Systems

Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).

Exploitation Status

Active exploitation confirmed in the wild. No patch available at time of disclosure.

Business Impact

Organizations using Cisco SD-WAN Manager face immediate risk from active exploitation with no vendor patch available. SD-WAN infrastructure compromise could enable network-wide lateral movement, traffic interception, or service disruption. All deployment models affected, including government/FedRAMP environments. Mitigation limited to workarounds until patch release.

Urgency

🔴 Immediate

Recommended Actions

  • Review Cisco's security advisory for CVE-2026-20245 immediately and implement all published workarounds
  • Restrict network access to Cisco Catalyst SD-WAN Manager interfaces to trusted management networks only
  • Enable enhanced logging on SD-WAN Manager and monitor for unusual authentication attempts, configuration changes, or API activity
  • Inventory all Cisco SD-WAN Manager instances (on-prem and cloud) and verify deployment type to assess exposure
  • Establish incident response readiness for potential compromise and prepare to apply emergency patch when released