Cisco security patch release for CVE-2026-20245
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released security updates for Cisco Catalyst SD-WAN after CVE-2026-20245 was linked to root-level command execution, and customers were told to move to fixed software. The affected scope includes vManage, vSmart, and vBond, and Cisco said there were no workarounds. The flaw was already used in zero-day attacks, making the upgrade urgent for exposed deployments.
Related Happenings
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
Campaign
H score38
First: 25.06.2026 17:15
Last: 25.06.2026 17:15
Sources 1
How related:
From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices.
About this happening:
An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
CampaignHow related: From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices.
About this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco ThousandEyes and Nexus security patches
Security Patch Release
H score31
First: 21.05.2026 15:04
Last: 21.05.2026 15:04
Sources 1
About this happening:
Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...
Cisco ThousandEyes and Nexus security patches
Security Patch ReleaseAbout this happening: Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...
Cisco security patch release for CVE-2026-20182
Security Patch Release
H score60
First: 14.05.2026 20:45
Last: 14.05.2026 20:45
Sources 1
About this happening:
Cisco released updates for CVE-2026-20182, a maximum-severity authentication bypass in Catalyst SD-WAN Controller/Manager, after the flaw was exploited in limite...
Cisco security patch release for CVE-2026-20182
Security Patch ReleaseAbout this happening: Cisco released updates for CVE-2026-20182, a maximum-severity authentication bypass in Catalyst SD-WAN Controller/Manager, after the flaw was exploited in limite...
Cisco security patch release for CVE-2026-20188
Security Patch Release
H score35
First: 06.05.2026 21:06
Last: 06.05.2026 21:06
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Cisco security patch release for CVE-2026-20188
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Timeline
-
25.06.2026 00:29 4 articles · 21d ago
Cisco releases security updates for CVE-2026-20245
Mitigation Patch UpdateCisco released security updates for CVE-2026-20245 in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) after warning that authenticated attackers could exploit the command injection flaw to gain root privileges and push unauthorized configuration changes to edge devices. Cisco said there were no workarounds and urged customers to upgrade to fixed software versions.
Show sources
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access — www.bleepingcomputer.com — 25.06.2026 00:29
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access — www.bleepingcomputer.com — 25.06.2026 00:29
- Cisco SD-WAN Zero-Day Exploited Months Before Patching — www.securityweek.com — 25.06.2026 09:08
- Cisco Vulnerability Exploited Months Before Disclosure, Google Warns — www.infosecurity-magazine.com — 25.06.2026 17:15