Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet
2026-06-05T14:51:45Z•40bc3f4e07529f39202c10cfd3772d050eff3e4ddb0916eeae996fb88e567cda
cisa-kevciscocisco-sd-wancisco-unified-cmcloud-abusecve-2026-20230cve-2026-20245cve-2026-45247disclosure-politicsemail-relayespionagefake-context-alignmentgamaredongoogle-geminilaw-enforcementmirasvitoperation-kratosoutlook-compromisepcpjackprompt-injectionsmart-homevs-code-zero-daywinrar
What happened
Multiple high-impact security developments: Cisco disclosed a privilege-escalation/file-upload command-injection in Catalyst SD‑WAN Manager (CVE-2026-20245) allowing authenticated attackers root access with no patch/workaround yet; Cisco also patched a high-severity SSRF in Unified CM with public PoC published (CVE-2026-20230). CISA added a critical Mirasvit Full Page Cache Warmer flaw (CVE-2026-45247, CVSS 9.3) to its KEV catalog. Researchers exposed a 230-node cloud email-relay network used by actor PCPJack, and Gamaredon leveraged a WinRAR flaw to deploy modular, near-fileless spyware in a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 40bc3f4e07529f39202c10cfd3772d050eff3e4ddb0916eeae996fb88e567cda
- Enrichment time
- 2026-06-05T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.