Cisco customers encounter another SD-WAN zero-day under attack
2026-06-09T14:51:43Z•c0f8c810e71157d334038b83cd9cc20f7d0aea53c4a5fc91b5a31121c91bead2
CiscoSD‑WANactive exploitationincident responsenetwork infrastructurepatchingunpatched vulnerabilityzero-day
What happened
CyberScoop reports that Cisco SD-WAN appliances are being targeted by an actively exploited zero-day — the seventh such SD‑WAN zero-day this year. The vulnerability (referenced in reporting as CVE-2026-20245) remains unpatched by Cisco, leaving customers exposed to active attacks against network infrastructure. Organizations using Cisco SD‑WAN should assume active exploitation, apply vendor workarounds/mitigations, increase monitoring and segmentation, and prioritize patching when a fix is released.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- c0f8c810e71157d334038b83cd9cc20f7d0aea53c4a5fc91b5a31121c91bead2
- Enrichment time
- 2026-06-09T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.