$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC CISA-KEV · HIGH
2026-06-11 high REL 7/10

Cisco Catalyst SD-WAN Manager Remote Command Execution Vulnerability

energyfinancegovernmenthealthcare

Cisco has disclosed a command injection vulnerability in Catalyst SD-WAN Manager that permits authenticated local attackers to execute arbitrary commands with root privileges through a malicious file upload. This affects the formerly-named SD-WAN vManage product. Organizations should apply vendor patches or implement workarounds by the June 2026 deadline.

Why it matters in Western Canada: Western Canadian energy, finance, and large public sector organizations frequently deploy SD-WAN solutions for network optimization. Exploitation could provide attackers direct access to critical network infrastructure and sensitive systems.

CVEs: CVE-2026-20245


Summary generated from the original advisory. Read the full source: cisa-kev

Source
https://nvd.nist.gov/vuln/detail/CVE-2026-20245
CVEs
CVE-2026-20245
Tags
cisco, sd-wan, command-injection, network-infrastructure, authentication-required
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)