Cisco customers encounter another SD-WAN zero-day under attack

2026-06-09T14:51:43Zc0f8c810e71157d334038b83cd9cc20f7d0aea53c4a5fc91b5a31121c91bead2
CiscoSD‑WANactive exploitationincident responsenetwork infrastructurepatchingunpatched vulnerabilityzero-day

What happened

CyberScoop reports that Cisco SD-WAN appliances are being targeted by an actively exploited zero-day — the seventh such SD‑WAN zero-day this year. The vulnerability (referenced in reporting as CVE-2026-20245) remains unpatched by Cisco, leaving customers exposed to active attacks against network infrastructure. Organizations using Cisco SD‑WAN should assume active exploitation, apply vendor workarounds/mitigations, increase monitoring and segmentation, and prioritize patching when a fix is released.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
c0f8c810e71157d334038b83cd9cc20f7d0aea53c4a5fc91b5a31121c91bead2
Enrichment time
2026-06-09T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.