Cisco alerts users to active exploitation of SD-WAN zero-day vulnerability
The company cautioned that no current patches are available and the flaw could allow an attacker to conduct command injection attacks.
Topic
7 articles found
The company cautioned that no current patches are available and the flaw could allow an attacker to conduct command injection attacks.
The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek.
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. [...]
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used
Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges. [...]
The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified CM Vulnerability appeared first on SecurityWeek.
Cloud security startup Upwind Security Inc. today announced it has integrated its runtime security platform with Cisco Cloud Control, the unified platform for agentic information technology operations that Cisco Systems Inc. unveiled at its Cisco Live 2026 conference. The integration, built through